WordPress < 4.5.0 Multiple Vulnerabilities

high Nessus Plugin ID 91100

Synopsis

The PHP application running on the remote web server is affected by multiple vulnerabilities.

Description

According to its self-reported version number, the WordPress application running on the remote web server is prior to 4.5.0.
It is, therefore, affected by the following vulnerabilities :

- A server-side request forgery vulnerability exists due improper request handling between a user and the server.
An attacker can exploit this, via a specially crafted request to the http.php script using octal or hexadecimal IP addresses, to bypass access restrictions and perform unintended actions. (CVE-2016-4029)

- A cross-site scripting vulnerability exists due to improper validation of user-supplied input to the 'first_comment_author' parameter. A context-dependent attacker can exploit this, via a specially crafted request, to execute arbitrary script code in a user's browser session. (CVE-2016-6634)

- A cross-site request forgery vulnerability exists due to a failure to require multiple steps, explicit confirmation, or a unique token when making HTTP requests. An attacker can exploit this by convincing a user to follow a specially crafted link. (CVE-2016-6635)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to WordPress version 4.5.0 or later.

See Also

https://wpvulndb.com/vulnerabilities/8473

https://wpvulndb.com/vulnerabilities/8474

https://wpvulndb.com/vulnerabilities/8475

https://codex.wordpress.org/Version_4.5#Security

Plugin Details

Severity: High

ID: 91100

File Name: wordpress_4_5_0.nasl

Version: 1.7

Type: remote

Family: CGI abuses

Published: 5/12/2016

Updated: 3/29/2019

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2016-6635

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:wordpress:wordpress

Required KB Items: installed_sw/WordPress, www/PHP, Settings/ParanoidReport

Exploit Ease: No exploit is required

Patch Publication Date: 4/12/2016

Vulnerability Publication Date: 3/30/2016

Reference Information

CVE: CVE-2016-4029, CVE-2016-6634, CVE-2016-6635

BID: 92355, 92390, 92400