CVE-2018-6389
Summary
| CVE | CVE-2018-6389 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-06 17:29:00 UTC |
| Updated | 2019-03-01 19:07:00 UTC |
| Description | In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times. |
Risk And Classification
Problem Types: CWE-400
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WordPress <= 4.9.4 - Application Denial of Service (DoS) (unpatched) | MISC | wpvulndb.com | Third Party Advisory |
| WordPress 'load-scripts.php' Lets Remote Users Consume Excessive I/O Resources and Deny Service - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Unpatched DoS Flaw Could Help Anyone Take Down WordPress Websites | MISC | thehackernews.com | Exploit, Third Party Advisory |
| WordPress Core - 'load-scripts.php' Denial of Service | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| WordPress CVE-2018-6389 Denial of Service Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| GitHub - s0md3v/Shiva: Improved DOS exploit for wordpress websites (CVE-2018-6389) | MISC | github.com | Exploit, Third Party Advisory |
| Information Security: How to DoS 29% of the World Wide Websites - CVE-2018-6389 | MISC | baraktawily.blogspot.fr | Exploit, Issue Tracking, Third Party Advisory |
| GitHub - WazeHell/CVE-2018-6389: CVE-2018-6389 Exploit In WordPress DoS | MISC | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.