webpack JS package <= 5.75.0 - Sandbox Bypass

2023-04-11 00:00
Anonymous

Strategic Overview

Status
Patched in 7.4.0
Affected PluginRestricted Site Access
Affected Version<= 7.3.5
CVSS8.3High
CVECVE-2023-28154
View all Restricted Site Access vulnerabilities

Vulnerability Overview

The JS package webpack is vulnerable to Sandbox Bypass in versions up to, and including, 5.75.0 due to mishandling magic comments. Some WordPress plugins and themes use this dependency, however, are not vulnerable to exploitation.

Technical Analysis

REMEDIATION: Update to version 7.4.0, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C