WordPress Plugin Vulnerability
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
The Splashing Images plugin has been identified as having two vulnerabilities. The first, CVE-2018-6195, could allow an authenticated attacker to inject PHP code into the current WordPress instance using specially crafted URLs. Depending on the active classes, this could lead to file deletion or remote code execution.
The second vulnerability, CVE-2018-6194, allows an attacker to inject client-side scripts into a WordPress page. These pages could then be seen by other users, potentially compromising them as well. An attacker could also bypass access controls to access other areas of the web application.
For further information please see:
Remediation steps
CVE Vulnerabilities
Last edited: 17 February 2020 12:57 pm