CVE-2020-28039Wordpress vulnerability

8 documents6 sources
Severity
9.1CRITICALNVD
EPSS
6.0%
top 9.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 2
Latest updateMay 24

Description

is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

NVDwordpress/wordpress< 5.5.2
Debianwordpress/wordpress< 5.5.3+dfsg1-1+3

Also affects: Debian Linux 10.0, 9.0, Ubuntu Linux 16.04, 18.04, 20.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-65h5-8qpr-9m3v: is_protected_meta in wp-includes/meta2022-05-24
OSV
CVE-2020-28039: is_protected_meta in wp-includes/meta2020-11-02
CVEList
CVE-2020-28039: is_protected_meta in wp-includes/meta2020-10-31

📋Vendor Advisories

1
Debian
CVE-2020-28039: wordpress - is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbit...2020

💬Community

3
Bugzilla
CVE-2020-28039 wordpress: protected meta that could lead to arbitrary file deletion [epel-all]2020-11-05
Bugzilla
CVE-2020-28039 wordpress: protected meta that could lead to arbitrary file deletion2020-11-05
Bugzilla
CVE-2020-28039 wordpress: protected meta that could lead to arbitrary file deletion [fedora-all]2020-11-05
CVE-2020-28039 — Wordpress vulnerability | cvebase