WordPress Core < 6.0.3 - Shared User Instance Weakness

2022-10-18 00:00
Ben Bidner

Strategic Overview

Status
Patched in 3.7.40
Affected Core
WordPress 6.0
Affected Version
3.6.1 – 6.0.2 · 25 branches
CVSS
3.7Low
Weakness type
CWE-488 · Exposure of Data Element to Wrong Session
CVE
CVE pending
View all WordPress 6.0 vulnerabilities

At a glance

This record tracks a low-severity Exposure of Data Element to Wrong Session vulnerability in the WordPress 6.0 WordPress release line, affecting 3.6.1 – 6.0.2 · 25 branches. It carries a CVSS score of 3.7 (reachable over the network). Exploitation requires no authentication. The issue is fixed in version 3.7.40; sites on affected versions should update now. Disclosed October 2022, reported by Ben Bidner.

Vulnerability Overview

WordPress Core in versions up to 6.0.3 had a weakness in how Share User Instances were handled. This fix appears to have been necessary to safely use the wp_set_current_user( 0 ); method to patch the previously mentioned XSS and CSRF in wp-mail.php and wp-trackback.php vulnerabilities. The previous functionality may have resulted in third party plugins or themes using the wp_set_current_user function in a way that could lead to privilege escalation and users being able to perform more actions than originally intended.

Technical Analysis

The vector marks this flaw as remotely reachable over the network, and no privileges on the target site, and no interaction from a victim user.

CWE-488: Exposure of Data Element to Wrong Session

The product does not sufficiently enforce boundaries between the states of different sessions, causing data to be provided to, or used by, the wrong session.

Remediation

Update to one of the following versions, or a newer patched version: 3.7.40, 3.8.40, 3.9.38, 4.0.37, 4.1.37, 4.2.34, 4.3.30, 4.4.29, 4.5.28, 4.6.25, 4.7.25, 4.8.21, 4.9.22, 5.0.18, 5.1.15, 5.2.17, 5.3.14, 5.4.12, 5.5.11, 5.6.10, 5.7.8, 5.8.6, 5.9.5, 6.0.3

How does WordSec protect against this?

The fix is the thing that ends this: updating to 3.7.40 is the step that ends it.

  • Alerts

External References

Related records

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C