CVE-2016-10148
published 2017-01-18CVE-2016-10148: The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the…
PriorityP421medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
1.64%
73.7th percentile
The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin parameter to wp-admin/admin-ajax.php, a related issue to CVE-2016-6896.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 4.6.1+dfsg-1 (bookworm) | wordpress 4.6.1+dfsg-1 (bookworm) |
| wordpress | wordpress | <= 4.5.5 | — |
| wordpress | wordpress | >= 0 < 4.6.1+dfsg-1 | 4.6.1+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.6.1+dfsg-1 | 4.6.1+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.6.1+dfsg-1 | 4.6.1+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.6.1+dfsg-1 | 4.6.1+dfsg-1 |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2016-10148: wordpress - The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in Word...
vendor_debian·2016·CVSS 4.3
CVE-2016-10148 [MEDIUM] CVE-2016-10148: wordpress - The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in Word...
The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin parameter to wp-admin/admin-ajax.php, a related issue to CVE-2016-6896.
Scope: local
bookworm: resolved (fixed in 4.6.1+dfsg-1)
bullseye: resolved (fixed in 4.6.1+dfsg-1)
forky: resolved (fixed in 4.6.1+dfsg-1)
sid: resolved (fixed in 4.6.1+dfsg-1)
trixie: resolved (fixed in 4.6.1+dfsg-1)
GHSA
GHSA-3wwg-h2fr-3v7w: The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions
ghsa_unreviewed·2022-05-17·CVSS 7.1
CVE-2016-10148 [HIGH] GHSA-3wwg-h2fr-3v7w: The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions
The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin parameter to wp-admin/admin-ajax.php, a related issue to CVE-2016-6896.
OSV
CVE-2016-10148: The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions
osv·2017-01-18·CVSS 4.3
CVE-2016-10148 [MEDIUM] CVE-2016-10148: The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions
The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin parameter to wp-admin/admin-ajax.php, a related issue to CVE-2016-6896.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2016/08/20/1http://www.securityfocus.com/bid/96847https://core.trac.wordpress.org/changeset/38168https://core.trac.wordpress.org/ticket/37490https://sumofpwn.nl/advisory/2016/path_traversal_vulnerability_in_wordpress_core_ajax_handlers.htmlhttp://www.openwall.com/lists/oss-security/2016/08/20/1http://www.securityfocus.com/bid/96847https://core.trac.wordpress.org/changeset/38168https://core.trac.wordpress.org/ticket/37490https://sumofpwn.nl/advisory/2016/path_traversal_vulnerability_in_wordpress_core_ajax_handlers.html
2017-01-18
Published