WordPress Core < 4.7.3 - Bypass URL Validation

2017-03-06 00:00
Daniel Chatfield

Strategic Overview

Status
Patched in 3.7.19
Affected CoreWordPress 4.7
Affected Version3.7 – 4.7.2 · 12 branches
CVSS6.1Medium
CVECVE-2017-6815
View all WordPress 4.7 vulnerabilities

Vulnerability Overview

In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.

Technical Analysis

REMEDIATION: Update to one of the following versions, or a newer patched version: 3.7.19, 3.8.19, 3.9.17, 4.0.16, 4.1.16, 4.2.13, 4.3.9, 4.4.8, 4.5.7, 4.6.4, 4.7.3 --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C