WordPress Core < 4.9 - Insecure Deserialization

2018-08-16 00:00
Sam Thomas

Strategic Overview

Status
Patched in 4.9
Affected CoreWordPress 4.9
Affected Version< 4.9
CVSS8.8High
CVECVE-2017-1000600
View all WordPress 4.9 vulnerabilities

Vulnerability Overview

WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time. This issue appears to have been partially, but not completely fixed in WordPress 4.9

Technical Analysis

REMEDIATION: Update to version 4.9, or a newer patched version --- IDENTIFIER: CWE-502 (Deserialization of Untrusted Data) The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C