CVE-2021-4451

The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar deserialization on the server. This deserialization can allow other plugin or theme exploits if vulnerable software is present (WordPress, and NinjaFirewall).
Configurations

Configuration 1 (hide)

cpe:2.3:a:nintechnet:ninjafirewall:*:*:*:*:*:wordpress:*:*

History

30 Oct 2024, 17:44

Type Values Removed Values Added
First Time Nintechnet ninjafirewall
Nintechnet
CPE cpe:2.3:a:nintechnet:ninjafirewall:*:*:*:*:*:wordpress:*:*
References () https://blog.nintechnet.com/security-issue-fixed-in-ninjafirewall-wp-edition/ - () https://blog.nintechnet.com/security-issue-fixed-in-ninjafirewall-wp-edition/ - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/1a1fc6c9-50cd-40fd-a777-9eed98aab797?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/1a1fc6c9-50cd-40fd-a777-9eed98aab797?source=cve - Third Party Advisory
CVSS v2 : unknown
v3 : 6.6
v2 : unknown
v3 : 7.2

16 Oct 2024, 16:38

Type Values Removed Values Added
Summary
  • (es) El complemento NinjaFirewall para WordPress es vulnerable a la deserialización de PHAR autenticada en versiones hasta la 4.3.3 incluida. Esto permite que atacantes autenticados realicen la deserialización de phar en el servidor. Esta deserialización puede permitir que otros complementos o temas exploten su seguridad si existe software vulnerable (WordPress y NinjaFirewall).

16 Oct 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-16 07:15

Updated : 2024-10-30 17:44


NVD link : CVE-2021-4451

Mitre link : CVE-2021-4451

CVE.ORG link : CVE-2021-4451


JSON object : View

Products Affected

nintechnet

  • ninjafirewall
CWE
CWE-502

Deserialization of Untrusted Data