4.3
CVE-2021-29450
- EPSS 2.09%
- Veröffentlicht 15.04.2021 22:15:12
- Zuletzt bearbeitet 21.11.2024 06:01:07
- Erkennungen
WordPress Authenticated disclosure of password-protected posts and pages
WordPress Core < 5.7.1 - Sensitive Information Disclosure
WordPress: Authenticated disclosure of password-protected posts and pages
Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress 5.7.1, along with the older affected versions via minor releases. It's strongly recommended that you keep auto-updates enabled to receive the fix.
Mögliche Gegenmaßnahme
WordPress: Update to one of the following versions, or a newer patched version: 4.7.20, 4.8.16, 4.9.17, 5.0.12, 5.1.9, 5.2.10, 5.3.7, 5.4.5, 5.5.4, 5.6.3, 5.7.1
WordPress Core: Install latest version
WordPress Core: Install latest version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Weitere Schwachstelleninformationen
SystemWordPress Core
≫
Produkt
WordPress
Version
[4.7, 4.7.20)
Version
[4.8, 4.8.16)
Version
[4.9, 4.9.17)
Version
[5.0, 5.0.12)
Version
[5.1, 5.1.9)
Version
[5.2, 5.2.10)
Version
[5.3, 5.3.7)
Version
[5.4, 5.4.5)
Version
[5.5, 5.5.4)
Version
[5.6, 5.6.3)
Version
[5.7, 5.7.1)
System
≫
Produkt
WordPress Core
Version
>= 4.7, < 5.7.1
System
≫
Produkt
WordPress Core
Version
>= 4.7, < 5.7.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.09% | 0.798 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
| security-advisories@github.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://lists.debian.org/debian-lts-announce/2021/04/msg00017.html
https://wordpress.org/news/category/security/
https://www.debian.org/security/2021/dsa-4896
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-pmmh-2f36-wvhq
https://www.wordfence.com/threat-intel/vulnerabilities/id/a57426d2-0ca4-405b-bfbf-0685e2c744a0
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-pmmh-2f36-wvhq