SCA: security update for wp-cli/wp-cli (GHSA-rwgm-f83r-v3qj)

high Tenable Cloud Security Plugin ID 418965

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- WP-CLI is the command-line interface for WordPress. An improper error handling in HTTPS requests
management in WP-CLI version 0.12.0 and later allows remote attackers able to intercept the communication
to remotely disable the certificate verification on WP-CLI side, gaining full control over the
communication content, including the ability to impersonate update servers and push malicious updates
towards WordPress instances controlled by the vulnerable WP-CLI agent, or push malicious updates toward
WP-CLI itself. The vulnerability stems from the fact that the default behavior of
`WP_CLI\Utils\http_request()` when encountering a TLS handshake error is to disable certificate validation
and retry the same request. The default behavior has been changed with version 2.5.0 of WP-CLI and the
`wp-cli/wp-cli` framework (via https://github.com/wp-cli/wp-cli/pull/5523) so that the
`WP_CLI\Utils\http_request()` method accepts an `$insecure` option that is `false` by default and
consequently that a TLS handshake failure is a hard error by default. This new default is a breaking
change and ripples through to all consumers of `WP_CLI\Utils\http_request()`, including those in separate
WP-CLI bundled or third-party packages. https://github.com/wp-cli/wp-cli/pull/5523 has also added an
`--insecure` flag to the `cli update` command to counter this breaking change. There is no direct
workaround for the default insecure behavior of `wp-cli/wp-cli` versions before 2.5.0. The workaround for
dealing with the breaking change in the commands directly affected by the new secure default behavior is
to add the `--insecure` flag to manually opt-in to the previous insecure behavior. (CVE-2021-29504)

See Also

https://github.com/advisories/GHSA-rwgm-f83r-v3qj

Plugin Details

Severity: High

ID: 418965

Version: Revision 1.5

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.04

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2021-29504

CVSS v3

Risk Factor: High

Base Score: 7.4

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/19/2021

Vulnerability Publication Date: 5/19/2021

Reference Information

CVE: CVE-2021-29504

cwe: CWE-295