QID 154102

Date Published: 2021-12-02

QID 154102: WordPress Information Disclosure Vulnerability (CVE-2021-39200)

WordPress is an open-source blogging tool and content management system based on PHP and MySQL. It has many features including a plug-in architecture and a template system.

In affected versions of WordPress CMS output data of the function wp_die() can be leaked under certain conditions, which can include data like nonces. It can then be used to perform actions on your behalf.

Affected versions:
WordPress 5.2 to 5.8

A remote attacker can gain unauthorized access to sensitive information on the system.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to upgrade to a fixed version WordPress 5.8.1 or later versions to remediate this vulnerability.

    CVEs related to QID 154102

    Software Advisories
    Advisory ID Software Component Link
    WordPress URL Logo wordpress.org/download/releases/