18 Jun 2023

Remote Code Execution (RCE) Vulnerability in Template Debugger

Today, Patchstack claimed there was a cross-site request forgery (CSRF) vulnerability in the latest version of the WordPress plugin Template Debugger, but didn’t provide the information needed to check on their claim. In looking into this, we found what probably is what they are labeling as a CSRF vulnerability, but it is actually a much more serious vulnerability. The vulnerability allows an attacker to run arbitrary code on the website.

...


This post provides insights on a vulnerability in a WordPress plugin not discovered by us, where the discoverer hadn't provided the details needed for us to confirm the vulnerability while we were adding it to the data set for our service, so the rest of its contents are limited to subscribers of our service.

If you were using our service, you would have already been warned about this vulnerability if your website is vulnerable due to it. You can try out our service for free and then see the rest of the details of the vulnerability.

For existing customers, please log in to your account to view the contents of the post.

Leave a Reply

Your email address will not be published.