WordPress Core < 5.5.2 - Privilege Escalation via XML-RPC
2020-10-29 00:00
Justin TranStrategic Overview
StatusPatched in 3.7.35
Affected CoreWordPress 5.5
Affected Version
3.7 – 5.5.1 · 20 branchesCVSS8.8High
CVE
CVE-2020-28035Vulnerability Overview
WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.
Technical Analysis
REMEDIATION: Update to one of the following versions, or a newer patched version: 3.7.35, 3.8.35, 3.9.33, 4.0.32, 4.1.32, 4.2.29, 4.3.25, 4.4.24, 4.5.23, 4.6.20, 4.7.19, 4.8.15, 4.9.16, 5.0.11, 5.1.7, 5.2.8, 5.3.5, 5.4.3, 5.5.2 --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C