CVE-2013-5739
published 2013-09-12CVE-2013-5739: The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users…
PriorityP415low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.76%
75.5th percentile
The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 3.6.1+dfsg-1 (bookworm) | wordpress 3.6.1+dfsg-1 (bookworm) |
| wordpress | wordpress | <= 3.6 | — |
| wordpress | wordpress | >= 0 < 3.6.1+dfsg-1 | 3.6.1+dfsg-1 |
| wordpress | wordpress | >= 0 < 3.6.1+dfsg-1 | 3.6.1+dfsg-1 |
| wordpress | wordpress | >= 0 < 3.6.1+dfsg-1 | 3.6.1+dfsg-1 |
| wordpress | wordpress | >= 0 < 3.6.1+dfsg-1 | 3.6.1+dfsg-1 |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv3.5LOW
vendor_debian3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2013-5739: wordpress - The default configuration of WordPress before 3.6.1 does not prevent uploads of ...
vendor_debian·2013·CVSS 3.5
CVE-2013-5739 [LOW] CVE-2013-5739: wordpress - The default configuration of WordPress before 3.6.1 does not prevent uploads of ...
The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.
Scope: local
bookworm: resolved (fixed in 3.6.1+dfsg-1)
bullseye: resolved (fixed in 3.6.1+dfsg-1)
forky: resolved (fixed in 3.6.1+dfsg-1)
sid: resolved (fixed in 3.6.1+dfsg-1)
trixie: resolved (fixed in 3.6.1+dfsg-1)
GHSA
GHSA-v4p8-jvp4-22m6: The default configuration of WordPress before 3
ghsa_unreviewed·2022-05-17
CVE-2013-5739 [LOW] CWE-79 GHSA-v4p8-jvp4-22m6: The default configuration of WordPress before 3
The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.
OSV
CVE-2013-5739: The default configuration of WordPress before 3
osv·2013-09-12·CVSS 3.5
CVE-2013-5739 [LOW] CVE-2013-5739: The default configuration of WordPress before 3
The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.
No detection rules found.
No public exploits indexed.
http://codex.wordpress.org/Version_3.6.1http://core.trac.wordpress.org/changeset/25322http://wordpress.org/news/2013/09/wordpress-3-6-1/http://www.debian.org/security/2013/dsa-2757http://codex.wordpress.org/Version_3.6.1http://core.trac.wordpress.org/changeset/25322http://wordpress.org/news/2013/09/wordpress-3-6-1/http://www.debian.org/security/2013/dsa-2757
2013-09-12
Published