PT-2021-4505 · WordPress · Wordpress

Ehti

·

Published

2021-09-09

·

Updated

2024-03-06

·

CVE-2021-39200

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WordPress versions prior to 5.8.1
Description The issue is related to the wp die() function in WordPress, which can leak output data under certain conditions, including sensitive information like nonces. This leaked data can be used to perform actions on behalf of the user. The exploitation of this issue may allow a remote attacker to execute arbitrary code.
Recommendations For versions prior to 5.8.1, update to WordPress 5.8.1 or later to receive the fix. It is strongly recommended to keep auto-updates enabled to ensure the receipt of the fix. As a temporary workaround, consider restricting access to the wp die() function until a patch is available.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2021-05143
BIT-WORDPRESS-2021-39200
BIT-WORDPRESS-MULTISITE-2021-39200
CVE-2021-39200
DSA-4985-1
GHSA-M9HC-7V5Q-X8Q5

Affected Products

Wordpress