'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2026-07-06 | |
| Rule Name: | Social Warfare Remote Code Execution Vulnerability (CVE-2019-9978) | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | Social Warfare WordPress plugin <= 3.5.2 contains a remote code execution vulnerability in the settings import functionality. Unauthenticated attackers can exploit this vulnerability by manipulating the swp_debug and swp_url parameters to execute arbitrary code on the server. | |
| Impact: | Unauthenticated attackers can execute arbitrary code on the server with the privileges of the web server process, potentially leading to complete system compromise, data theft, and further lateral movement within the network. | |
| Affected OS: | Windows, Linux, Others | |
| Reference: | ||
| Solutions |
|---|
| Please contact the software vendor to update the software patch. |