CVE-2008-2392Improper Input Validation in Wordpress

Severity
9.0CRITICALNVD
EPSS
1.9%
top 16.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 21
Latest updateMay 1

Description

Unrestricted file upload vulnerability in WordPress 2.5.1 and earlier might allow remote authenticated administrators to upload and execute arbitrary PHP files via the Upload section in the Write Tabs area of the dashboard.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 8.0 | Impact: 10.0

Affected Packages3 packages

debiandebian/wordpress< wordpress 2.5.1-4 (bookworm)
Debianwordpress/wordpress< 2.5.1-4+3

🔴Vulnerability Details

2
GHSA
GHSA-g734-67mf-ffrp: Unrestricted file upload vulnerability in WordPress 22022-05-01
OSV
CVE-2008-2392: Unrestricted file upload vulnerability in WordPress 22008-05-21

📋Vendor Advisories

2
Red Hat
wordpress: Malicious File Execution Vulnerability2008-05-19
Debian
CVE-2008-2392: wordpress - Unrestricted file upload vulnerability in WordPress 2.5.1 and earlier might allo...2008

💬Community

1
Bugzilla
CVE-2008-2392 wordpress: Malicious File Execution Vulnerability2008-05-22