WordPress Core < 5.8.2 - ca-bundle.crt contains expired certificate DST Root CA X3

2021-11-10 00:00
Anonymous

Strategic Overview

Status
Patched in 5.2.13
Affected CoreWordPress 5.8
Affected Version5.2 – 5.8.1 · 8 branches
CVSS5.3Medium
CVEN/A
View all WordPress 5.8 vulnerabilities

Vulnerability Overview

WordPress Core in various versions less than version 5.8.2 contained an expired DST Root CA X3 certificate. There is no significant security risk to most WordPress users.

Technical Analysis

REMEDIATION: Update to one of the following versions, or a newer patched version: 5.2.13, 5.3.10, 5.4.8, 5.5.7, 5.6.6, 5.7.4, 5.8.2 --- IDENTIFIER: CWE-324 (Use of a Key Past its Expiration Date) The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C