CVE-2020-28037 log
Source |
|
Severity | Critical |
Remote | Yes |
Type | Arbitrary code execution |
Description | is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation). |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-1257 | wordpress | 5.5.1-1 | 5.5.3-1 | Critical | Fixed |
Date | Advisory | Group | Package | Severity | Type |
---|---|---|---|---|---|
03 Nov 2020 | ASA-202011-3 | AVG-1257 | wordpress | Critical | multiple issues |
References |
---|
https://github.com/WordPress/wordpress-develop/commit/2ca15d1e5ce70493c5c0c096ca0c76503d6da07c |