Περιγραφή
The GWD Connect plugin for WordPress is vulnerable to missing authorization to limited code execution in all versions up to, and including, 2.9. This is due to the plugin-s standalone agent endpoints (gwd-backup.php and gwd-logs.php) not verifying authentication when the API key has not been configured, which is the default state. This makes it possible for unauthenticated attackers - on unregistered installations only, in certain environments - to execute arbitrary code on the server via the update_agent action, which writes attacker-supplied PHP code to the agent file.
CVSS 4.8EPSS 0.27299999999999996%Κίνδυνος 0.49
Προβολή πηγής- Δημοσίευση
- 2026-05-12 09:16:55
- Επηρεαζόμενες εκδόσεις
- <=2.9
- Τύπος
- Installed app
- Διάνυσμα
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N