Twigify <= 1.1.2 & AP Twig Bridge <= 1.0 & Content Template Engine <= 0.9.4 - Running Vulnerable Twig Package
Strategic Overview
Vulnerability Overview
The Twigify plugin for WordPress is running a vulnerable version of Twig (1.16.3) in all versions up to, and including, 1.1.2, the AP Twig Bridge plugin for WordPress is running a vulnerable version of Twig (1.5.0) in all versions up to, and including, 1.0, and the Content Template Engine plugin for WordPress is running a vulnerable version of Twig (1.22.3) in all versions up to, and including, 0.9.4. This version of Twig contains many security vulnerabilities, though none have been confirmed exploitable in the Twigify or AP Twig Bridge plugins.
Technical Analysis
REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-1395 (Dependency on Vulnerable Third-Party Component) The product has a dependency on a third-party component that contains one or more known vulnerabilities.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C