CERT-In Vulnerability Note
CIVN-2017-0180
Multiple Security Vulnerability in WordPress
Original Issue Date:December 06, 2017
Severity Rating: MEDIUM
Software Affected
- WordPress 4.9 and earlier.
Overview
A vulnerability has been reported in WordPress, which could be exploited by remote attacker to compromise the targeted website.
Description
Multi-vector attack vulnerability
These vulnerabilities exist in WordPress due to use of substring instead of hash for newloguser, improper handling of html elements, ability to upload JavaScript files for users who do not have the unfiltered_html capability. A remote attacker could exploit this vulnerability as part of a multi-vector attack to the affected sites. Successful exploitation of this vulnerability could allow an attacker to compromise the targeted website.
Solution
Apply appropriate fixes as issued by vendor in the following link
https://wordpress.org/
Vendor Information
WordPress
https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
References
WordPress
https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|