Record summary

CVE-2016-10960 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.

Description

The wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php publish parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 8, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHWordPress wSecure Lite < 2.4 - Remote Code ExecutionCVSS 8.8

WordPress wsecure plugin before 2.4 is susceptible to remote code execution via shell metacharacters in the wsecure-config.php publish parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected WordPress site.

Remediation

Update to the latest version of WordPress wSecure Lite plugin (2.4 or higher) to fix the vulnerability.

WeaknessesCWE-20
Authorsdaffainfo
Template tagscve2016cvewordpresswp-pluginrcejoomlaserviceprovidervkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:joomlaserviceprovider:wsecure:*:*:*:*:lite:wordpress:*:*
Google: inurl:"/wp-content/plugins/wsecure"

Source: ProjectDiscovery

References

3