Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2007-0540Wordpress vulnerability

6 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
7.8%
top 8.04%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJan 29
Latest updateMay 1

Description

WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to a file with a binary content type, which is downloaded even though it cannot contain usable pingback data.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/wordpress< wordpress 2.1.0-1 (bookworm)
Debianwordpress/wordpress< 2.1.0-1+3

🔴Vulnerability Details

2
GHSA
GHSA-9xf3-qrpw-5fjc: WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that cor2022-05-01
OSV
CVE-2007-0540: WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that cor2007-01-29

💥Exploits & PoCs

1
Exploit-DB
WordPress Core 1.x/2.0.x - Pingback SourceURI Denial of Service / Information Disclosure2007-01-24

📋Vendor Advisories

1
Debian
CVE-2007-0540: wordpress - WordPress allows remote attackers to cause a denial of service (bandwidth or thr...2007

💬Community

1
Bugzilla
wordpress < 2.1 multiple vulnerabilities2007-01-30
CVE-2007-0540 — Debian Wordpress vulnerability | cvebase