WordPress Core < 6.0.3 - Information Disclosure (Multi-Part Email Leak)

2022-10-18 00:00
Thomas Kräftner

Strategic Overview

Status
Patched in 3.7.40
Affected Core
WordPress 6.0
Affected Version
3.6.1 – 6.0.2 · 25 branches
CVSS
3.7Low
Weakness type
CWE-200 · Exposure of Sensitive Information to an Unauthorized Actor
CVE
CVE pending
View all WordPress 6.0 vulnerabilities

At a glance

This record tracks a low-severity Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the WordPress 6.0 WordPress release line, affecting 3.6.1 – 6.0.2 · 25 branches. It carries a CVSS score of 3.7 (reachable over the network). Exploitation requires no authentication. The issue is fixed in version 3.7.40; sites on affected versions should update now. Disclosed October 2022, reported by Thomas Kräftner.

Vulnerability Overview

WordPress Core is vulnerable to information disclosure via a REST-API endpoint in versions up to 6.0.3. The endpoint for terms and tags did not perform enough validation on the user requesting information about terms and tags for a given post. This made it possible for users with access to terms and tags, such as a contributor, to determine those details on all posts not belonging to them, even when in a private status. This does not reveal critical information, and as such it is not likely to be exploited.

Technical Analysis

The vector marks this flaw as remotely reachable over the network, and no privileges on the target site, and no interaction from a victim user.

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Reaching this weakness in WordPress 6.0 3.6.1 – 6.0.2 · 25 branches takes a caller who can reach the endpoint. Sensitive information exposure means data the application intended to keep internal is returned to a caller who should not be able to see it.

The disclosed data — credentials, tokens, customer records or internal paths — is usually worth more as material for a follow-up attack than as an end in itself. For WordPress 6.0 the fix is 3.7.40: builds 3.6.1 – 6.0.2 · 25 branches are affected, anything from 3.7.40 onward is not.

Remediation

Update to one of the following versions, or a newer patched version: 3.7.40, 3.8.40, 3.9.38, 4.0.37, 4.1.37, 4.2.34, 4.3.30, 4.4.29, 4.5.28, 4.6.25, 4.7.25, 4.8.21, 4.9.22, 5.0.18, 5.1.15, 5.2.17, 5.3.14, 5.4.12, 5.5.11, 5.6.10, 5.7.8, 5.8.6, 5.9.5, 6.0.3

How does WordSec protect against this?

The fix is the thing that ends this: updating to 3.7.40 is the step that ends it.

  • Alerts

External References

Related records

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C