CVE-2021-39200
Summary
| CVE | CVE-2021-39200 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-09 22:15:00 UTC |
| Updated | 2021-12-14 21:38:00 UTC |
| Description | WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like nonces. It can then be used to perform actions on your behalf. This has been patched in WordPress 5.8.1, along with any older affected versions via minor releases. It's strongly recommended that you keep auto-updates enabled to receive the fix. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| HackerOne |
MISC |
hackerone.com |
|
| WordPress: Information Disclosure in wp_die() via JSONP, leading to CSRF · Advisory · WordPress/wordpress-develop · GitHub |
CONFIRM |
github.com |
|
| Debian -- Security Information -- DSA-4985-1 wordpress |
DEBIAN |
www.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 154102 WordPress Information Disclosure Vulnerability (CVE-2021-39200)
- 178825 Debian Security Update for wordpress (DSA 4985-1)
- 180285 Debian Security Update for wordpress (CVE-2021-39200)