custom-content-type-manager Wordpress plugin can be used by an administrator to achieve arbitrary PHP remote code execution.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/6b3d0736-7f08-4403-95eb-4385cb206f9e | third party advisory exploit |
https://blog.nettitude.com/uk/custom-content-type-manager-remote-code-execution | third party advisory exploit |
https://github.com/craftsmancoding/custom-content-type-manager/blob/master/readme.txt | third party advisory release notes |