PatchSiren

WordPress CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited WordPress CVE published 2021-11-03

CVE-2020-25213

CVE-2020-25213 is a remote code execution vulnerability in the WordPress File Manager Plugin that CISA included in its Known Exploited Vulnerabilities catalog on 2021-11-03. Because it is listed as actively exploited, organizations should treat exposed or unpatched installations as urgent remediation candidates and follow vendor update guidance.

Known exploited WordPress CVE published 2021-11-03

CVE-2020-11738

CVE-2020-11738 is a file download vulnerability affecting the WordPress Snap Creek Duplicator Plugin. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, which indicates confirmed exploitation and makes remediation a priority for any environment using the plugin.

Known exploited WordPress CVE published 2021-11-03

CVE-2019-9978

CVE-2019-9978 is a Cross-Site Scripting (XSS) issue affecting the WordPress Social Warfare Plugin. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, which indicates known exploitation and makes remediation urgent. CISA’s listed action is to apply updates per vendor instructions.

MEDIUM Wordpress CVE published 2017-01-18

CVE-2016-6897

CVE-2016-6897 is a WordPress core cross-site request forgery (CSRF) issue in the wp_ajax_update_plugin handler. According to the CVE record, the bug could let a remote attacker abuse an authenticated browser session because the nonce check was performed too late in the request flow. NVD rates the issue at CVSS 6.5 (medium) and maps it to CWE-352. WordPress versions before 4.6 are listed as affected.

HIGH Wordpress CVE published 2017-01-18

CVE-2016-6896

CVE-2016-6896 is an authenticated directory traversal issue in WordPress’s wp_ajax_update_plugin handler. The flaw lets a remote user with the required login context supply traversal sequences in the plugin parameter to wp-admin/admin-ajax.php, which can lead to reading certain text files or triggering denial-of-service conditions. The supplied NVD record classifies the issue as CWE-22 and rates it CVSS 7.1 High.

MEDIUM Wordpress CVE published 2017-01-18

CVE-2016-10148

CVE-2016-10148 is an access-control flaw in WordPress core’s wp_ajax_update_plugin handler. In affected versions before 4.6, the code called get_plugin_data before checking the update_plugins capability, which could let authenticated users access plugin information they should not have been able to read. NVD classifies affected WordPress versions through 4.5.5 and assigns a CVSS v3.0 score of 4.3 (MEDIUM) [truncated]

HIGH Wordpress CVE published 2017-01-15

CVE-2017-5493

CVE-2017-5493 is a WordPress Multisite vulnerability in which key generation in wp-includes/ms-functions.php did not use sufficiently random numbers. In affected WordPress versions before 4.7.1, a remote attacker could abuse crafted site or user signup flows to bypass intended access restrictions. WordPress addressed the issue in the 4.7.1 security and maintenance release.

HIGH Wordpress CVE published 2017-01-15

CVE-2017-5492

CVE-2017-5492 is a cross-site request forgery issue in WordPress widget-editing accessibility mode. A remote attacker could trick an authenticated victim into submitting a widgets-access request without consent, potentially changing widget settings in the victim's session. WordPress addressed the issue in version 4.7.1.

MEDIUM Wordpress CVE published 2017-01-15

CVE-2017-5491

CVE-2017-5491 affects WordPress versions before 4.7.1. The issue is described as a possible bypass of intended posting restrictions in wp-mail.php when an attacker uses a spoofed mail server name matching mail.example.com. In practice, this means mail-based posting controls could be weakened under the documented conditions. WordPress addressed the issue in the 4.7.1 security and maintenance release.

MEDIUM Wordpress CVE published 2017-01-15

CVE-2017-5490

CVE-2017-5490 is a cross-site scripting (XSS) issue in WordPress versions before 4.7.1. The vulnerable path involves theme-name fallback handling in wp-includes/class-wp-theme.php, with related admin-side theme installer logic noted in wp-admin/includes/class-theme-installer-skin.php. A crafted theme directory name could be rendered into web output and allow arbitrary script or HTML injection. The NVD rec [truncated]

HIGH Wordpress CVE published 2017-01-15

CVE-2017-5489

CVE-2017-5489 is a high-severity Cross-Site Request Forgery issue in WordPress versions before 4.7.1. The published record describes remote attackers potentially hijacking a victim’s authentication through vectors involving a Flash file upload. The NVD entry maps the issue to CWE-352 and a network-reachable, user-interaction-required attack surface, with vendor references pointing to the WordPress 4.7.1 s [truncated]

MEDIUM Wordpress CVE published 2017-01-15

CVE-2017-5488

CVE-2017-5488 covers multiple cross-site scripting (XSS) issues in WordPress’s admin update flow. The vulnerable area is wp-admin/update-core.php, where plugin name or version header data could be injected into an admin-facing page; WordPress addressed the issue in 4.7.1.

MEDIUM Wordpress CVE published 2017-01-15

CVE-2017-5487

CVE-2017-5487 is a WordPress 4.7 REST API information disclosure issue. According to the CVE record, the users controller did not properly restrict listings of post authors, allowing a remote attacker to obtain sensitive information through a wp-json/wp/v2/users request. The issue is rated medium severity and is fixed in WordPress 4.7.1.