PT-2019-5216 · WordPress · Wordpress

Published

2019-09-11

·

Updated

2023-02-04

·

CVE-2019-17669

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WordPress versions prior to 5.2.4
Description The issue is related to a Server Side Request Forgery (SSRF) vulnerability. This occurs because URL validation does not consider the interpretation of a name as a series of hex characters. Exploitation of this issue may allow a remote attacker to access confidential data, compromise data integrity, and cause a denial of service.
Recommendations For versions prior to 5.2.4, update to version 5.2.4 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive data and configuring the server to validate URLs more strictly until a patch is applied. Avoid using URLs that could be interpreted as a series of hex characters in the affected API endpoints until the issue is resolved.

Fix

SSRF

Weakness Enumeration

Related Identifiers

BDU:2020-01945
CVE-2019-17669
DLA-1980-1
DSA-4599-1
DSA-4677-1

Affected Products

Wordpress