Beta

Report

External featured image from bing <= 1.0.2 is vulnerable to Remote Code Execution (RCE) vulnerability

Subscriber
Published
2024-10-08

The External featured image from bing plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute code on the server.

CVSS

Score:9.9

Severity:Critical

Version: 1.0.2

The plugin vendor has not patched this vulnerability at the moment.