This vulnerability is moderately dangerous and expected to become exploited. Vulnerabilities like this one are used in mass-exploit campaigns. Attackers use these to attack thousands of websites at a time, regardless of traffic size or popularity. Learn more.
As immediate action, update the affected plugin. If you're unable to do so, ask your hosting provider or web developer for help.
This is not a false positive. The Client Mode "Edit Content" which is meant to grant limited content edit access to users on Breakdance is by default vulnerable to RCE. Regardless of the existing warnings in place, code execution on the lowest permission available is against common access control principles and should not be made possible. Researcher advisory - https://snicco.io/vulnerability-disclosure/breakdance/client-mode-remote-code-execution-breakdance-1-7-0
Attackers can run any command on the server from anywhere in the world.
CVSS score is a way to evaluate and rank reported vulnerabilities in a standardized and repeatable way but which is not ideal for WordPress.
We advise to mitigate or resolve the vulnerability immediately.
Patchstack has issued a mitigation rule to block any attacks until an official patch becomes available, can be tested and be safely applied.
9 Feb, 2024
Early warning sent out to Patchstack customers
3 Apr, 2024
Published by Patchstack
3 Apr, 2024