CVE-2018-6389

HIGH LAB

Wordpress < 4.9.2 - Denial of Service

Title source: rule

Description

In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.

Exploits (23)

exploitdb WORKING POC
by Barak Tawily · pythondosphp
https://www.exploit-db.com/exploits/43968
nomisec WORKING POC 127 stars
by s0md3v · poc
https://github.com/s0md3v/Shiva
nomisec WORKING POC 81 stars
by safebuffer · poc
https://github.com/safebuffer/CVE-2018-6389
nomisec WRITEUP 13 stars
by ItinerisLtd · poc
https://github.com/ItinerisLtd/trellis-cve-2018-6389
nomisec WORKING POC 10 stars
by knqyf263 · poc
https://github.com/knqyf263/CVE-2018-6389
nomisec WORKING POC 6 stars
by omidsec · poc
https://github.com/omidsec/CVE-2018-6389
nomisec WORKING POC 3 stars
by ianxtianxt · poc
https://github.com/ianxtianxt/CVE-2018-6389
nomisec WORKING POC 3 stars
by Zazzzles · poc
https://github.com/Zazzzles/Wordpress-DOS
nomisec SCANNER 2 stars
by m3ssap0 · poc
https://github.com/m3ssap0/wordpress_cve-2018-6389
nomisec WORKING POC 2 stars
by JavierOlmedo · poc
https://github.com/JavierOlmedo/wordpress-cve-2018-6389
nomisec WORKING POC 2 stars
by dsfau · poc
https://github.com/dsfau/wordpress-CVE-2018-6389
nomisec WORKING POC 1 stars
by vineetkia · poc
https://github.com/vineetkia/Wordpress-DOS-Attack-CVE-2018-6389
nomisec WORKING POC 1 stars
by armaanpathan12345 · poc
https://github.com/armaanpathan12345/WP-DOS-Exploit-CVE-2018-6389
nomisec WORKING POC 1 stars
by JulienGadanho · poc
https://github.com/JulienGadanho/cve-2018-6389-php-patcher
nomisec WRITEUP 1 stars
by yolabingo · poc
https://github.com/yolabingo/wordpress-fix-cve-2018-6389
nomisec WORKING POC
by amit-pathak009 · poc
https://github.com/amit-pathak009/CVE-2018-6389-FIX
nomisec WORKING POC
by alessiogilardi · poc
https://github.com/alessiogilardi/PoC---CVE-2018-6389
nomisec WORKING POC
by fakedob · poc
https://github.com/fakedob/tvsz
nomisec STUB
by mudhappy · poc
https://github.com/mudhappy/Wordpress-Hack-CVE-2018-6389
nomisec WRITEUP
by BlackRouter · poc
https://github.com/BlackRouter/cve-2018-6389
nomisec WORKING POC
by thechrono13 · poc
https://github.com/thechrono13/PoC---CVE-2018-6389
nomisec WORKING POC
by Jetserver · poc
https://github.com/Jetserver/CVE-2018-6389-FIX
nomisec WRITEUP
by rastating · poc
https://github.com/rastating/modsecurity-cve-2018-6389

Scores

CVSS v3 7.5
EPSS 0.8748
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-400
Status published
Products (1)
wordpress/wordpress < 4.9.2
Published Feb 06, 2018
Tracked Since Feb 18, 2026