CVE-2020-4050
In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved.
Does this matter?
Lower severity and a low EPSS score (1.41%). Track it; it rarely justifies an emergency change on its own.
Description
In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged by low privileged users. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).
- CVSS 3.1
- 3.1 LOWCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.41% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-288
- Affected
- wordpress/wordpress · fedoraproject/fedora · debian/debian linux
- Source
- security-advisories@github.com
References
- https://github.com/WordPress/wordpress-develop/commit/b8dea76b495f0072523106c6ec46b9ea0d2a0920Patch
- https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-4vpv-fgg2-gcqcThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00000.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/09/msg00011.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/773N2ZV7QEMBGKH6FBKI6Q5S3YJMW357/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ODNHXVJS25YVWYQHOCICXTLIN5UYJFDN/
- https://wordpress.org/news/2020/06/wordpress-5-4-2-security-and-maintenance-release/Release Notes, Vendor Advisory
- https://www.debian.org/security/2020/dsa-4709Third Party Advisory
- https://github.com/WordPress/wordpress-develop/commit/b8dea76b495f0072523106c6ec46b9ea0d2a0920Patch
- https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-4vpv-fgg2-gcqcThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00000.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/09/msg00011.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/773N2ZV7QEMBGKH6FBKI6Q5S3YJMW357/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ODNHXVJS25YVWYQHOCICXTLIN5UYJFDN/
- https://wordpress.org/news/2020/06/wordpress-5-4-2-security-and-maintenance-release/Release Notes, Vendor Advisory
- https://www.debian.org/security/2020/dsa-4709Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.