QID 154134
Date Published: 2023-05-02
QID 154134: WordPress Multiple Vulnerabilities: Security Release 6.0.3
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database.
Multiple vulnerabilities such as Data Exposure, CSRF, Open redirect, SQL injection (SQLi) and Cross-Site-Scripting (XSS) are identified in affected versions of WordPress. Details of these vulnerabilities can be found at WordPress Security Release 6.0.2.
Affected Versions:
WordPress versions prior to 6.0.3
QID Detection Logic(Unauthenticated):
This QID sends a HTTP GET request and checks for vulnerable version of WordPress running on the target application.
Successful exploitation of these vulnerabilities could harm Confidentiality, Availability and Integrity of the target application.
Solution
Customers are advised to upgrade to the latest version of WordPress to remediate these vulnerabilities. For more information regarding these vulnerabilities please visit WordPress Security Release.
Vendor References
- WordPress Security Release -
wordpress.org/news/2022/10/wordpress-6-0-3-security-release/
CVEs related to QID 154134
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WordPress 6.0.3 |
|