Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2018-6389Uncontrolled Resource Consumption in Wordpress

Severity
7.5HIGHNVD
EPSS
87.5%
top 0.54%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedFeb 6
Latest updateJul 31

Description

In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-pxcx-cprx-mr28: In WordPress through 42022-05-14
OSV
CVE-2018-6389: In WordPress through 42018-02-06

💥Exploits & PoCs

1
Exploit-DB
WordPress Core - 'load-scripts.php' Denial of Service2018-02-05

📋Vendor Advisories

1
Debian
CVE-2018-6389: wordpress - In WordPress through 4.9.2, unauthenticated attackers can cause a denial of serv...2018

📄Research Papers

1
arXiv
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights2024-07-31

💬Community

15
HackerOne
CVE-2018-6389 exploitation - using scripts loader2024-02-13
HackerOne
CVE-2018-6389 exploitation - using scripts loader2023-04-20
HackerOne
DoS at █████(CVE-2018-6389)2023-03-24
HackerOne
DoS at ████████ (CVE-2018-6389)2023-02-24
HackerOne
DoS of https://research.adobe.com/ via CVE-2018-6389 exploitation2022-10-13
CVE-2018-6389 — Uncontrolled Resource Consumption | cvebase