CVE-2013-5739
The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the…
Does this matter?
Lower severity and a low EPSS score (1.76%). Track it; it rarely justifies an emergency change on its own.
Description
The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
- EPSS
- 1.76% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- wordpress/wordpress
- Source
- cve@mitre.org
References
- http://codex.wordpress.org/Version_3.6.1Vendor Advisory
- http://core.trac.wordpress.org/changeset/25322Exploit, Patch
- http://wordpress.org/news/2013/09/wordpress-3-6-1/Patch, Vendor Advisory
- http://www.debian.org/security/2013/dsa-2757
- http://codex.wordpress.org/Version_3.6.1Vendor Advisory
- http://core.trac.wordpress.org/changeset/25322Exploit, Patch
- http://wordpress.org/news/2013/09/wordpress-3-6-1/Patch, Vendor Advisory
- http://www.debian.org/security/2013/dsa-2757
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.