nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-10960 CVE-2016-10960
HIGHNuclei
joomlaserviceprovider wsecure Improper Input Validation
Record summary
CVE-2016-10960 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.
Description
The wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php publish parameter.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 8, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
Nuclei templates
1ProjectDiscoveryHIGHWordPress wSecure Lite < 2.4 - Remote Code ExecutionCVSS 8.8
WordPress wsecure plugin before 2.4 is susceptible to remote code execution via shell metacharacters in the wsecure-config.php publish parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected WordPress site.
Remediation
Update to the latest version of WordPress wSecure Lite plugin (2.4 or higher) to fix the vulnerability.
WeaknessesCWE-20
Authorsdaffainfo
Template tagscve2016cvewordpresswp-pluginrcejoomlaserviceprovidervkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:joomlaserviceprovider:wsecure:*:*:*:*:lite:wordpress:*:*
Google: inurl:"/wp-content/plugins/wsecure"
https://www.pluginvulnerabilities.com/2016/07/12/remote-code-execution-rce-vulnerability-in-wsecure-lite/ https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-wsecure-lite-remote-code-execution-2-3/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10960 https://wordpress.org/plugins/wsecure/#developers https://github.com/ARPSyndicate/cvemon
Source: ProjectDiscovery
References
3wordpress.org
https://wordpress.org/plugins/wsecure pluginvulnerabilities.com
https://www.pluginvulnerabilities.com/2016/07/12/remote-code-execution-rce-vulnerability-in-wsecure-lite