cbcvebase.
CVE-2008-5113
published 2008-11-17

CVE-2008-5113: WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and…

PriorityP412medium4CVSS 2.0
AVNACHAuNCNIPAP
EPSS
1.33%
67.9th percentile
WordPress 2.6.3 relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier for remote attackers to conduct delayed and persistent cross-site request forgery (CSRF) attacks via crafted cookies, as demonstrated by attacks that (1) delete user accounts or (2) cause a denial of service (loss of application access). NOTE: this issue relies on the presence of an independent vulnerability that allows cookie injection.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianwordpress< wordpress 2.5.1-10 (bookworm)wordpress 2.5.1-10 (bookworm)
wordpresswordpress
wordpresswordpress>= 0 < 2.5.1-102.5.1-10
wordpresswordpress>= 0 < 2.5.1-102.5.1-10
wordpresswordpress>= 0 < 2.5.1-102.5.1-10
wordpresswordpress>= 0 < 2.5.1-102.5.1-10

CVSS provenance

nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:N/I:P/A:P
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.