CVE · Critical

CVE-2017-9841 — Cloudflare [cloudflare] < 1.1.12

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2017-9841 Cloudflare [cloudflare] < 1.1.12 Improper Control of Generation of Code ('Code Injection') Critical 9.8 < 1.1.12 1.1.12 2017-06-27

CVE-2017-9841

The Cloudflare plugin for WordPress before version 1.1.12 contains a vulnerability in its bundled PHPUnit library that permits unauthenticated attackers to execute arbitrary PHP code by sending POST requests with PHP code snippets to the exposed eval-stdin.php file. This flaw affects sites where the vendor directory is publicly accessible, allowing remote code execution through the vulnerable PHPUnit component included in the plugin.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.