CVE · Critical

CVE-2024-22144 — Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.23.56

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-22144 Anti-Malware Security and Brute-Force Firewall [gotmls] < 4.23.56 Improper Control of Generation of Code ('Code Injection') Critical 9.0 < 4.23.56 4.23.56 2024-03-12

CVE-2024-22144

The Anti-Malware Security and Brute-Force Firewall plugin for WordPress contained a remote code execution flaw in versions before 4.23.56 that could permit an attacker to run arbitrary commands on an affected site. Exploitation of this vulnerability could lead to unauthorized website control through backdoor access. The issue was identified by stealthcopter and has been remediated in version 4.23.56 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.