Remote Code Execution Vulnerability in Ads by Datafeedr.com for WordPress
CVE-2023-5843
9CRITICAL
Summary
The Ads by datafeedr.com plugin for WordPress has a critical vulnerability that allows unauthenticated users to execute arbitrary code on the server due to improper sanitization in the 'dfads_ajax_load_ads' function. This flaw affects versions up to and including 1.1.3, enabling attackers to exploit the plugin and compromise server integrity. Organizations using this plugin should prioritize updates to mitigate potential attacks.
Affected Version(s)
Ads by datafeedr.com * <= 1.1.3
References
EPSS Score
8% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lana Codes