Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 22 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Disable Wordpress Update Notifications And Auto-update Email Notifications Project
Disable Wordpress Update Notifications And Auto-update Email Notifications Project is-human Plugin |
|
| CPEs | cpe:2.3:a:disable_wordpress_update_notifications_and_auto-update_email_notifications_project:is-human__plugin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Disable Wordpress Update Notifications And Auto-update Email Notifications Project
Disable Wordpress Update Notifications And Auto-update Email Notifications Project is-human Plugin |
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Is-human
Is-human is-human Wordpress Plugin Wordpress Wordpress wordpress |
|
| Vendors & Products |
Is-human
Is-human is-human Wordpress Plugin Wordpress Wordpress wordpress |
Wed, 15 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Oct 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WordPress plugin is-human <= v1.4.2 contains an eval injection vulnerability in /is-human/engine.php that can be triggered via the 'type' parameter when the 'action' parameter is set to 'log-reset'. The root cause is unsafe use of eval() on user-controlled input, which can lead to execution of attacker-supplied PHP and OS commands. This may result in arbitrary code execution as the webserver user, site compromise, or data exfiltration. The is-human plugin was made defunct in June 2008 and is no longer available for download. This vulnerability was exploited in the wild in March 2012. | |
| Title | WordPress Plugin is-human <= v1.4.2 Eval Injection RCE | |
| Weaknesses | CWE-95 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-15T11:13:50.601Z
Reserved: 2025-10-10T13:59:10.279Z
Link: CVE-2011-10033
Updated: 2025-10-15T18:47:47.664Z
Status : Deferred
Published: 2025-10-15T02:15:31.020
Modified: 2026-04-15T00:35:42.020
Link: CVE-2011-10033
No data.
OpenCVE Enrichment
Updated: 2025-10-21T09:41:15Z