CVE-2020-11026

HIGH

WordPress <5.4.1 - Authenticated RCE

Title source: llm
STIX 2.1

Description

In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

References (4)

Core 4
Core References
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2020/dsa-4677
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/05/msg00011.html

Scores

CVSS v3 8.7
EPSS 0.0209
EPSS Percentile 79.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Details

CWE
CWE-79 CWE-707
Status published
Products (5)
debian/debian_linux 8.0
debian/debian_linux 9.0
debian/debian_linux 10.0
wordpress/wordpress 5.4
wordpress/wordpress 3.7 - 3.7.33
Published Apr 30, 2020
Tracked Since Feb 18, 2026