WordPress < 3.1.3 Multiple Vulnerabilities

critical Nessus Network Monitor Plugin ID 9108

Synopsis

The remote server is hosting an outdated installation of WordPress that is vulnerable to multiple attack vectors.

Description

Versions of WordPress prior to 3.1.3 are susceptible to the following vulnerabilities :

- An unspecified flaw exists related to media security. (CVE-2011-3122)
- An unspecified flaw exists related to security hardening. (CVE-2011-3125)
- A flaw exists that allows remote attackers to determine usernames of non-authors via canonical redirects. (CVE-2011-3126)
- A flaw exists which fails to prevent rendering for admin or login pages inside a frame in a third-party HTML document. A remote attacker may exploit this to conduct clickjacking attacks via a crafted web site. (CVE-2011-3127)
- A flaw exists that treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to 'wp-includes/post.php'. (CVE-2011-3128)
- An unspecified flaw exists related to file upload functionaliy. (CVE-2011-3129)
- An unspecified flaw exists in 'wp-includes/taxonomy.php' related to taxonomy query hardening which may allow an attacker to conduct an SQL injection attack. (CVE-2011-3130)

Solution

Upgrade to WordPress 3.3.2, or later.

See Also

http://wordpress.org/news/2011/05/wordpress-3-1-3

Plugin Details

Severity: Critical

ID: 9108

Family: CGI

Published: 2/26/2016

Updated: 3/6/2019

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 8.2

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:C

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:X/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:wordpress:wordpress

Patch Publication Date: 5/25/2011

Vulnerability Publication Date: 5/25/2011

Reference Information

CVE: CVE-2011-3122, CVE-2011-3125, CVE-2011-3126, CVE-2011-3127, CVE-2011-3128, CVE-2011-3129, CVE-2011-3130

BID: 47709, 47995, 49730