CVE-2023-5201
CRITICAL EXPLOITEDOpenHook <= 4.3.0 - Authenticated Remote Code Execution via PHP Shortcode
Title source: llmExploitation Summary
CVE-2023-5201 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server. This requires the [php] shortcode setting to be enabled on the vulnerable site.
References (3)
Core 3
Core References
Third Party Advisory
https://plugins.trac.wordpress.org/browser/thesis-openhook/tags/4.3.0/inc/shortcodes.php#L28
Scores
CVSS v3
9.9
EPSS
0.0143
EPSS Percentile
69.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
VulnCheck KEV
2023-09-29
CWE
CWE-94
Status
published
Products (2)
brazenlygeek/OpenHook
< 4.3.0
rickbeckman/openhook
< 4.3.0
Published
Sep 30, 2023
Tracked Since
Feb 18, 2026