Files
splunk-security_content/stories/wordpress_vulnerabilities.yml

25 lines
1.2 KiB
YAML

name: WordPress Vulnerabilities
id: baeaee14-e439-4c95-91e8-aaedd8265c1c
version: 2
creation_date: '2024-02-22'
modification_date: '2026-05-13'
author: Michael Haag, Splunk
status: production
description: This analytic story provides a collection of analytics that detect potential exploitation of WordPress vulnerabilities. The analytics are focused on the detection of known vulnerabilities in WordPress plugins and themes.
narrative: The following collection of analytics are focused on the detection of known vulnerabilities in WordPress plugins and themes. The analytics are focused on the detection of known vulnerabilities in WordPress plugins and themes.
references:
- https://attack.mitre.org/techniques/T1190
- https://github.com/Tornad0007/CVE-2024-25600-Bricks-Builder-plugin-for-WordPress/blob/main/exploit.py
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-25600
- https://op-c.net/blog/cve-2024-25600-wordpresss-bricks-builder-rce-flaw-under-active-exploitation/
- https://thehackernews.com/2024/02/wordpress-bricks-theme-under-active.html
cve:
- CVE-2024-25600
category:
- Adversary Tactics
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection