CERT-In Vulnerability Note
CIVN-2022-0023
Multiple Vulnerabilities in WordPress
Original Issue Date:January 14, 2022
Severity Rating: HIGH
Software Affected
- WordPress Version prior to 5.8.3
Overview
Multiple Vulnerabilities have been reported in WordPress that could allow an attacker to bypass security restrictions on the targeted system.
Description
These vulnerabilities exist in WordPress due to weak or compromised credentials and improper impose of security restrictions. An attacker could exploit these vulnerabilities by trigger remote code execution, security restriction bypass and cross-site scripting on the targeted system.
Successful exploitation of these vulnerabilities could allow an attacker to gain administrator privileges on a targeted system.
Solution
Apply appropriate fixes as issued by vendor in the following link:
https://wordpress.org/news/2022/01/wordpress-5-8-3-security-release/
Vendor Information
WordPress
https://wordpress.org/news/2022/01/wordpress-5-8-3-security-release/
References
WordPress
https://wordpress.org/news/2022/01/wordpress-5-8-3-security-release/
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|