Remote Code Execution in Ad Inserter Plugin for WordPress
CVE-2019-15324
8.8HIGH
Summary
The Ad Inserter plugin for WordPress, prior to version 2.4.22, contains a security flaw that allows an attacker to execute arbitrary code remotely. This vulnerability poses a significant risk to websites using the plugin, potentially leading to unauthorized access and control over the affected systems. It is crucial for site administrators to update the plugin to the latest version to mitigate any security threats associated with this vulnerability.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved