CVE Database /
CVE-2017-9841
CVE · Critical
CVE-2017-9841 — Cloudflare [cloudflare] < 1.1.12
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2017-9841
|
Cloudflare [cloudflare] < 1.1.12 |
Improper Control of Generation of Code ('Code Injection') |
Critical
9.8
|
< 1.1.12
|
1.1.12 |
2017-06-27 |
—
|
CVE-2017-9841
The Cloudflare plugin for WordPress before version 1.1.12 contains a vulnerability in its bundled PHPUnit library that permits unauthenticated attackers to execute arbitrary PHP code by sending POST requests with PHP code snippets to the exposed eval-stdin.php file. This flaw affects sites where the vendor directory is publicly accessible, allowing remote code execution through the vulnerable PHPUnit component included in the plugin.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings