• XSS.stack #1 – первый литературный журнал от юзеров форума

Wordpress RCE vulnerability for versions 6.4 & 6.4.1

marcorossi

RAID-массив
Пользователь
Регистрация
28.11.2022
Сообщения
90
Реакции
30
WordPress has released version 6.4.2 that contains a patch for a critical severity vulnerability that could allow attackers to execute PHP code on the site and potentially lead to a full site takeover.

Their own security team stated the following vulnerability in this release.
A Remote Code Execution vulnerability that is not directly exploitable in core, however the security team feels that there is a potential for high severity when combined with some plugins, especially in multisite installs

Version 6.4 was vulnerable to a Property Oriented Programming (POP) chain flaw that could be used for arbitrary PHP code execution, albeit under specific circumstances. Those circumstances require the target website to carry a PHP object injection flaw, which could be introduced with a vulnerable plug-in, or an add-on. Together, the flaws become critical in severity.

Sources:
Technical analysis: https://www.wordfence.com/blog/2023...te-code-execution-patched-in-wordpress-6-4-2/
https://www.bleepingcomputer[.]com/...s-pop-chain-exposing-websites-to-rce-attacks/
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх