SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-20086

A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4.

HIGH 7.5EPSS 1.06%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.06%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code injection. It is possible to initiate the attack remotely.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
1.06% probability · 63th percentile
CISA KEV
Not listed
Weakness
CWE-94
Affected
automattic/vaultpress
Source
cna@vuldb.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.