Pipdig Power Pack (P3) <= 4.7.3 - Backdoor

2019-03-29 00:00
Mikey Veenstra

Strategic Overview

Status
Patched in 4.8.0
Affected PluginPipdig Power Pack (P3)
Affected Version<= 4.7.3
CVSS9.8Critical
CVEN/A
View all Pipdig Power Pack (P3) vulnerabilities

Vulnerability Overview

The Pipdig Power Pack(p3) plugin for WordPress is contained a backdoor in versions before 4.8.0. Obfuscated code was present which allows for various backdoor functionality including unauthenticated password reset, unauthenticated database deletion, unusual scheduled remote calls, and undisclosed content and configuration rewrites.

Technical Analysis

REMEDIATION: Update to version 4.8.0, or a newer patched version --- IDENTIFIER: CWE-912 (Hidden Functionality) The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C