CVE-2021-29504

Summary

CVECVE-2021-29504
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2021-06-07 21:15:00 UTC
Updated2021-06-17 15:33:00 UTC
DescriptionWP-CLI is the command-line interface for WordPress. An improper error handling in HTTPS requests management in WP-CLI version 0.12.0 and later allows remote attackers able to intercept the communication to remotely disable the certificate verification on WP-CLI side, gaining full control over the communication content, including the ability to impersonate update servers and push malicious updates towards WordPress instances controlled by the vulnerable WP-CLI agent, or push malicious updates toward WP-CLI itself. The vulnerability stems from the fact that the default behavior of `WP_CLI\Utils\http_request()` when encountering a TLS handshake error is to disable certificate validation and retry the same request. The default behavior has been changed with version 2.5.0 of WP-CLI and the `wp-cli/wp-cli` framework (via https://github.com/wp-cli/wp-cli/pull/5523) so that the `WP_CLI\Utils\http_request()` method accepts an `$insecure` option that is `false` by default and consequently that a TLS handshake failure is a hard error by default. This new default is a breaking change and ripples through to all consumers of `WP_CLI\Utils\http_request()`, including those in separate WP-CLI bundled or third-party packages. https://github.com/wp-cli/wp-cli/pull/5523 has also added an `--insecure` flag to the `cli update` command to counter this breaking change. There is no direct workaround for the default insecure behavior of `wp-cli/wp-cli` versions before 2.5.0. The workaround for dealing with the breaking change in the commands directly affected by the new secure default behavior is to add the `--insecure` flag to manually opt-in to the previous insecure behavior.

Risk And Classification

Problem Types: CWE-295

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Wp-cli Wp-cli All All All All

References

ReferenceSourceLinkTags
Add `--insecure` flag to `core download` & `core update` commands by schlessera · Pull Request #186 · wp-cli/core-command · GitHub MISC github.com
Add `--insecure` flag to `package install` command by schlessera · Pull Request #138 · wp-cli/package-command · GitHub MISC github.com
Disable automatic retry by default on certificate validation error by schlessera · Pull Request #5523 · wp-cli/wp-cli · GitHub MISC github.com
Add `--insecure` flag to `core|plugin verify-checksums` commands by schlessera · Pull Request #86 · wp-cli/checksum-command · GitHub MISC github.com
Improper Certificate Validation in WP-CLI framework · Advisory · wp-cli/wp-cli · GitHub CONFIRM github.com
Add `--insecure` flag to `config create` & `config shuffle-salts` commands by schlessera · Pull Request #128 · wp-cli/config-command · GitHub MISC github.com
Add `--insecure` flag to `plugin|theme install` & `plugin\theme update` commands by schlessera · Pull Request #287 · wp-cli/extension-command · GitHub MISC github.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report