CVE-2015-5227
high
CVSS v3
8.8
CVSS v2
6.8
VIR risk
8.8
Description
The Landing Pages plugin before 1.9.2 for WordPress allows remote attackers to execute arbitrary code via the url parameter.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — https://wordpress.org/plugins/landing-pages/#developers
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| inboundnow | wordpress_landing_pages | {"endIncluding":"1.9.1"} | |
References
CWEs
CWE-74
Verify integrity in audit chain (admin only). AS-IS.