Rewterz
Rewterz Threat Alert – Cisco Alerts About Actively Exploited Zero-Day Vulnerability in IOS XE Software – Active IOCs
October 18, 2023
Rewterz
Rewterz Threat Advisory – ICS: Rockwell Automation FactoryTalk Linx Vulnerability
October 18, 2023

Rewterz Threat Advisory – Multiple WordPress Plugins Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2023-45208

D-Link DAP-X1860 could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by a command injection vulnerability. By using a specially crafted crafted SSID, an attacker could exploit this vulnerability to execute arbitrary commands on the system.

Impact

  • Gain Access
  • Cross-site Scripting

Indicators Of Compromise

CVE

  • CVE-2023-45655
  • CVE-2023-45643
  • CVE-2023-45645
  • CVE-2023-45647
  • CVE-2023-45651
  • CVE-2023-45650
  • CVE-2023-45748
  • CVE-2023-45654

Affected Vendors

WordPress

Affected Products

  • PixFields plugin for WordPress 0.7.0
  • CPT Shortcode Generator Plugin for WordPress 1.0
  • WP Open Street Map Plugin for WordPress 1.25
  • Constant Contact Forms by MailMunch Plugin for WordPress 2.0.10
  • WP Attachments Plugin for WordPress 5.0.6
  • HTML5 Maps Plugin for WordPress 1.7.1.4
  • MailChimp Forms by MailMunch Plugin for WordPress 3.1.4
  • Comments Ratings Plugin for WordPress 1.1.7

Remediation

Upgrade to the latest version of Plugin, available from the WordPress Plugin Directory

CVE-2023-45655

CVE-2023-45643

CVE-2023-45645

CVE-2023-45647

CVE-2023-45651

CVE-2023-45650

CVE-2023-45748

CVE-2023-45654