WordPress Core 2.1.1 - Supply Chain Compromise

2007-03-02 00:00
Anonymous

Strategic Overview

Status
Patched in 2.1.2
Affected CoreWordPress 2.1
Affected Version2.1.1
CVSS9.8Critical
CVEN/A
View all WordPress 2.1 vulnerabilities

Vulnerability Overview

Version 2.1.1 of WordPress was injected with malicious code that supplied attackers with backdoor access to WordPress sites.

Technical Analysis

REMEDIATION: Update to version 2.1.2, or a newer patched version --- IDENTIFIER: CWE-506 (Embedded Malicious Code) The product contains code that appears to be malicious in nature.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C