QID 154146
Date Published: 2024-01-03
QID 154146: WordPress Multiple Vulnerabilities: Security Release 6.4.2
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database.
WordPress Security Release 6.4.2 addresses multiple bug fixes and a Remote Code Execution (RCE) vulnerability that is not directly exploitable in core, however there is a potential for high severity when combined with some plugins, especially in multisite installs.
Affected Versions:
WordPress versions prior to 6.4.2
QID Detection Logic (Unauthenticated):
This QID sends an HTTP GET request and checks for the vulnerable version of WordPress running on the target application.
Successful exploitation of these vulnerabilities could harm Confidentiality, Availability and Integrity of the target application.
Solution
Customers are advised to upgrade to WordPress 6.4.2 or later to remediate this vulnerability. For more information, please refer WordPress Security Release.
Vendor References
- WordPress Security Release -
wordpress.org/news/2023/12/wordpress-6-4-2-maintenance-security-release/
CVEs related to QID 154146
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WordPress Security Release |
|