---
title: "CVE-2021-44223"
canonical: "https://kb.cynergy.app/space/MD/923599158/CVE-2021-44223"
format: markdown
---
**Description**

Certain versions of [Wordpress](https://cve.report/software/wordpress/wordpress) from [Wordpress](https://cve.report/vendor/wordpress) contain the following vulnerability:

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the [WordPress.org](http://WordPress.org) Plugin Directory but is not yet present in that directory.

**Published On**

11/25/2021

**Updated On**

11/30/2021

**Trending**

FALSE

**CWE**


**Exploit**

[https://vavkamil.cz/2021/11/25/wordpress-plugin-confusion-update-can-get-you-pwned/](https://vavkamil.cz/2021/11/25/wordpress-plugin-confusion-update-can-get-you-pwned/) 

**Mitigation:**

![image](media://ed7e4012-0ebf-47aa-aaf9-431ede7b0580)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

- Please update to the latest version

**Reference**

|  |  |  |
| --- | --- | --- |
| Introducing “Update URI” plugin header in WordPress 5.8 – Make WordPress Core | [http://make.wordpress.org](http://make.wordpress.org)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| WordPress Plugin Confusion: How an update can get you pwned | Kamil Vavra @vavkamil | [http://vavkamil.cz](http://vavkamil.cz)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |