WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Wordpress | Wordpress | * | 5.8 (excluding) |
| Wordpress | Ubuntu | bionic | * |
| Wordpress | Ubuntu | focal | * |
| Wordpress | Ubuntu | hirsute | * |
| Wordpress | Ubuntu | impish | * |
| Wordpress | Ubuntu | trusty | * |
| Wordpress | Ubuntu | upstream | * |
| Wordpress | Ubuntu | xenial | * |