CVE-2016-6635
published 2016-08-07CVE-2016-6635: Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5…
PriorityP342high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
2.49%
82.8th percentile
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 4.5+dfsg-1 (bookworm) | wordpress 4.5+dfsg-1 (bookworm) |
| wordpress | wordpress | <= 4.4.2 | — |
| wordpress | wordpress | >= 0 < 4.5+dfsg-1 | 4.5+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.5+dfsg-1 | 4.5+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.5+dfsg-1 | 4.5+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.5+dfsg-1 | 4.5+dfsg-1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2016-6635: wordpress - Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_te...
vendor_debian·2016·CVSS 8.8
CVE-2016-6635 [HIGH] CVE-2016-6635: wordpress - Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_te...
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option.
Scope: local
bookworm: resolved (fixed in 4.5+dfsg-1)
bullseye: resolved (fixed in 4.5+dfsg-1)
forky: resolved (fixed in 4.5+dfsg-1)
sid: resolved (fixed in 4.5+dfsg-1)
trixie: resolved (fixed in 4.5+dfsg-1)
GHSA
GHSA-g94h-w5p9-mvxc: Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions
ghsa_unreviewed·2022-05-17
CVE-2016-6635 [HIGH] CWE-352 GHSA-g94h-w5p9-mvxc: Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option.
OSV
CVE-2016-6635: Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions
osv·2016-08-07·CVSS 8.8
CVE-2016-6635 [HIGH] CVE-2016-6635: Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option.
No detection rules found.
No public exploits indexed.
Qualys
Hackers Are Having a Field Day with Stolen Credentials
blogs_qualys·2017-01-10
Hackers Are Having a Field Day with Stolen Credentials
Login credentials have always been a weak link in cybersecurity’s protection chain, a situation that’s worsening. However, this trend could be reversed with a bit of effort from end users, website owners and software vendors.
## 2016: The Year of Stolen Credentials
Hackers made hay of the sorry state of credential security in 2016. They stole millions of username and password combinations from online services of all shapes and sizes. Blogs and discussion forums were hit particularly hard.
Exploiting credentials is an old attack vector that still works wonders for hackers. In its 2016 Data Breach Investigations Report (DBIR), Verizon added a section about credentials, revealing that 63% of data breaches involved weak, default or stolen passwords.
“This statistic drives our recommendatio
Qualys
Hackers Are Having a Field Day with Stolen Credentials | Qualys
blogs_qualys·2017-01-10
Hackers Are Having a Field Day with Stolen Credentials | Qualys
Login credentials have always been a weak link in cybersecurity’s protection chain, a situation that’s worsening. However, this trend could be reversed with a bit of effort from end users, website owners and software vendors.
### 2016: The Year of Stolen Credentials
Hackers made hay of the sorry state of credential security in 2016. They stole millions of username and password combinations from online services of all shapes and sizes. Blogs and discussion forums were hit particularly hard.
Exploiting credentials is an old attack vector that still works wonders for hackers. In its 2016 Data Breach Investigations Report (DBIR), Verizon added a section about credentials, revealing that 63% of data breaches involved weak, default or stolen passwords.
“This statistic drives our recommendati
Bugzilla
CVE-2016-4029 CVE-2016-6634 CVE-2016-6635 wordpress: 4.5 release security fixes
bugzilla·2016-08-08·CVSS 8.6
CVE-2016-4029 [HIGH] CVE-2016-4029 CVE-2016-6634 CVE-2016-6635 wordpress: 4.5 release security fixes
CVE-2016-4029 CVE-2016-6634 CVE-2016-6635 wordpress: 4.5 release security fixes
Wordpress 4.5 release contains multiple security fixes.
External References:
https://codex.wordpress.org/Version_4.5#Security
Discussion:
Hi
This bug mentions CVE-2016-6633 as beeing assigned for wordpress fix in 4.5. Is this correct? The CVE seems to be assigned to the following phpmyadmin issue:
https://www.phpmyadmin.net/security/PMASA-2016-56/
---
(In reply to Salvatore Bonaccorso from comment #1)
> Hi
>
> This bug mentions CVE-2016-6633 as beeing assigned for wordpress fix in 4.5.
> Is this correct? The CVE seems to be assigned to the following phpmyadmin
> issue:
>
> https://www.phpmyadmin.net/security/PMASA-2016-56/
Hi Salvatore,
You are correct, the third CVE fixed in the 4.5 release is indee
http://codex.wordpress.org/Version_4.5http://www.debian.org/security/2016/dsa-3681https://github.com/WordPress/WordPress/commit/9b7a7754133c50b82bd9d976fb5b24094f658aabhttps://wpvulndb.com/vulnerabilities/8475http://codex.wordpress.org/Version_4.5http://www.debian.org/security/2016/dsa-3681https://github.com/WordPress/WordPress/commit/9b7a7754133c50b82bd9d976fb5b24094f658aabhttps://wpvulndb.com/vulnerabilities/8475
2016-08-07
Published