Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-34636 | The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar deserialization on the server. This deserialization can allow other plugin or theme exploits if vulnerable software is present (WordPress, and NinjaFirewall). |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 30 Oct 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nintechnet
Nintechnet ninjafirewall |
|
| CPEs | cpe:2.3:a:nintechnet:ninjafirewall:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Nintechnet
Nintechnet ninjafirewall |
Wed, 16 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ninjatechnologiesnetwork
Ninjatechnologiesnetwork ninja Firewall |
|
| CPEs | cpe:2.3:a:ninjatechnologiesnetwork:ninja_firewall:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ninjatechnologiesnetwork
Ninjatechnologiesnetwork ninja Firewall |
|
| Metrics |
ssvc
|
Wed, 16 Oct 2024 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and including, 4.3.3. This allows authenticated attackers to perform phar deserialization on the server. This deserialization can allow other plugin or theme exploits if vulnerable software is present (WordPress, and NinjaFirewall). | |
| Title | NinjaFirewall <= 4.3.3 - Authenticated PHAR Deserialization | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-10-16T19:07:11.134Z
Reserved: 2024-10-15T18:41:39.775Z
Link: CVE-2021-4451
Updated: 2024-10-16T19:07:05.891Z
Status : Analyzed
Published: 2024-10-16T07:15:11.770
Modified: 2024-10-30T17:44:27.477
Link: CVE-2021-4451
No data.
OpenCVE Enrichment
No data.
EUVD