

Rewterz Threat Advisory – CVE-2019-8071 – Adobe Download Manager Privilege Escalation Vulnerability
October 16, 2019
Rewterz Threat Alert – Diving Into Sodinokibi Ransomware
October 16, 2019
Rewterz Threat Advisory – CVE-2019-8071 – Adobe Download Manager Privilege Escalation Vulnerability
October 16, 2019
Rewterz Threat Alert – Diving Into Sodinokibi Ransomware
October 16, 2019Severity
Medium
Analysis Summary
WordPress 5.2.3 and prior versions are affected by multiple vulnerabilities. An attacker could exploit some of these vulnerabilities to take control of an affected website. Updated versions of WordPress 5.1 and earlier are also available for any users who have not yet updated to 5.2. Following are the issues found in 5.2.3. that are now fixed in version 5.2.4.
- An issue where stored XSS (cross-site scripting) could be added via the Customizer.
- A method of viewing unauthenticated posts.
- A way to create a stored XSS to inject Javascript into style tags.
- A method to poison the cache of JSON GET requests via the Vary: Origin header.
- A server-side request forgery in the way that URLs are validated.
- Issues related to referrer validation in the admin.
WordPress 5.2.4 is a short-cycle security release. The next major release will be version 5.3.
Impact
Website Takeover
Affected Vendors
WordPress
Affected Products
WordPress 5.2.3
Remediation
Upgrade to WordPress 5.2.4.