WordPress Plainview Activity Monitor plugin version 20161228 authenticated remote code execution exploit.
1b629fd8e9e33122cb936beab9fbfa2decfb180fdbec35129a79fd96bb42a793
WordPress Plainview Activity Monitor plugin is vulnerable to OS command injection which allows an attacker to remotely execute commands on the underlying system. Application passes unsafe user supplied data to ip parameter into activities_overview.php. Privileges are required in order to exploit this vulnerability. Vulnerable plugin version: 20161228 and possibly prior. Fixed plugin version: 20180826.
7ec3e2886cfeb10934e1758d21c4a3b07426bc1755426426441b88d92cfd7024
WordPress Plainview Activity Monitor plugin version 20161228 suffers from an OS command injection vulnerability.
cc18f6b6bbb91b393036a1b4f79ca9f2bacab314eba0b28ec164a11db7051572