VulnerabilityModified
CVE-2018-20148
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call.
CRITICAL 9.8EPSS 26.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 26.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 26.82% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- wordpress/wordpress · debian/debian linux
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/106220Third Party Advisory, VDB Entry
- https://blog.secarma.co.uk/labs/near-phar-dangerous-unserialization-wherever-you-areExploit, Third Party Advisory
- https://codex.wordpress.org/Version_4.9.9Product, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/02/msg00019.htmlMailing List, Third Party Advisory
- https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/Release Notes, Vendor Advisory
- https://wordpress.org/support/wordpress-version/version-5-0-1/Release Notes, Vendor Advisory
- https://wpvulndb.com/vulnerabilities/9171Vendor Advisory
- https://www.debian.org/security/2019/dsa-4401Third Party Advisory
- https://www.zdnet.com/article/wordpress-plugs-bug-that-led-to-google-indexing-some-user-passwords/Press/Media Coverage, Third Party Advisory
- https://www.zdnet.com/article/wordpress-vulnerability-affects-a-third-of-most-popular-websites-online/Press/Media Coverage, Third Party Advisory
- http://www.securityfocus.com/bid/106220Third Party Advisory, VDB Entry
- https://blog.secarma.co.uk/labs/near-phar-dangerous-unserialization-wherever-you-areExploit, Third Party Advisory
- https://codex.wordpress.org/Version_4.9.9Product, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/02/msg00019.htmlMailing List, Third Party Advisory
- https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/Release Notes, Vendor Advisory
- https://wordpress.org/support/wordpress-version/version-5-0-1/Release Notes, Vendor Advisory
- https://wpvulndb.com/vulnerabilities/9171Vendor Advisory
- https://www.debian.org/security/2019/dsa-4401Third Party Advisory
- https://www.zdnet.com/article/wordpress-plugs-bug-that-led-to-google-indexing-some-user-passwords/Press/Media Coverage, Third Party Advisory
- https://www.zdnet.com/article/wordpress-vulnerability-affects-a-third-of-most-popular-websites-online/Press/Media Coverage, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.