CVE-2020-4050
Summary
| CVE | CVE-2020-4050 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-12 16:15:00 UTC |
| Updated | 2023-11-07 03:23:00 UTC |
| Description | In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged by low privileged users. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34). |
Risk And Classification
Problem Types: CWE-288
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 31 | All | All | All |
| Operating System | Fedoraproject | Fedora | 32 | All | All | All |
| Operating System | Fedoraproject | Fedora | 31 | All | All | All |
| Operating System | Fedoraproject | Fedora | 32 | All | All | All |
| Application | Wordpress | Wordpress | All | All | All | All |
| Application | Wordpress | Wordpress | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 32 Update: wordpress-5.4.2-1.fc32 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| [SECURITY] Fedora 31 Update: wordpress-5.4.2-1.fc31 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| News – WordPress 5.4.2 Security and Maintenance Release – WordPress.org | MISC | wordpress.org | Vendor Advisory |
| [SECURITY] [DLA 2371-1] wordpress security update | MLIST | lists.debian.org | |
| [SECURITY] Fedora 31 Update: wordpress-5.4.2-1.fc31 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| Debian -- Security Information -- DSA-4709-1 wordpress | DEBIAN | www.debian.org | |
| [SECURITY] [DLA 2269-1] wordpress security update | MLIST | lists.debian.org | |
| WordPress: 'set-screen-option' filter misuse by plugins leading to privilege escalation · Advisory · WordPress/wordpress-develop · GitHub | CONFIRM | github.com | Third Party Advisory |
| [SECURITY] Fedora 32 Update: wordpress-5.4.2-1.fc32 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Administration: Add a new filter to extend set-screen-option. · WordPress/wordpress-develop@b8dea76 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.