PT-2020-17852 · WordPress · Wordpress

Ben Bidner

·

Published

2020-06-12

·

Updated

2024-03-06

·

CVE-2020-4050

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WordPress versions prior to 5.4.2 WordPress versions 5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34
Description The issue arises from the misuse of the set-screen-option filter's return value, allowing arbitrary user meta fields to be saved. This requires an admin to install a plugin that would misuse the filter, and once installed, it can be leveraged by low-privileged users.
Recommendations For versions prior to 5.4.2, update to version 5.4.2 or later to resolve the issue. For versions 5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34, update to the respective minor release or later to resolve the issue. As a temporary workaround, consider restricting the installation of plugins to prevent potential misuse of the set-screen-option filter until a patch is applied.

Fix

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

BDU:2020-03983
BIT-WORDPRESS-2020-4050
BIT-WORDPRESS-MULTISITE-2020-4050
CVE-2020-4050
DLA-2269-1
DLA-2371-1
DSA-4709-1
GHSA-4VPV-FGG2-GCQC

Affected Products

Wordpress