VulnerabilityModified
CVE-2013-4339
WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.
HIGH 7.5EPSS 7.49%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.49%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 7.49% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- wordpress/wordpress
- Source
- secalert@redhat.com
References
- http://codex.wordpress.org/Version_3.6.1Vendor Advisory
- http://core.trac.wordpress.org/changeset/25323Exploit, Patch
- http://core.trac.wordpress.org/changeset/25324Exploit, Patch
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116828.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116832.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/117118.html
- http://seclists.org/fulldisclosure/2013/Dec/174
- http://wordpress.org/news/2013/09/wordpress-3-6-1/Patch, Vendor Advisory
- http://www.debian.org/security/2013/dsa-2757
- http://www.osvdb.org/101181
- http://codex.wordpress.org/Version_3.6.1Vendor Advisory
- http://core.trac.wordpress.org/changeset/25323Exploit, Patch
- http://core.trac.wordpress.org/changeset/25324Exploit, Patch
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116828.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/116832.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-September/117118.html
- http://seclists.org/fulldisclosure/2013/Dec/174
- http://wordpress.org/news/2013/09/wordpress-3-6-1/Patch, Vendor Advisory
- http://www.debian.org/security/2013/dsa-2757
- http://www.osvdb.org/101181
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.