Fedora 31 : wordpress (2020-7701f49327)

high Nessus Plugin ID 136437

Language:

Synopsis

The remote Fedora host is missing a security update.

Description

**WordPress 5.4.1**

Security Updates

Seven security issues affect WordPress versions 5.4 and earlier. If you haven’t yet updated to 5.4, all WordPress versions since 3.7 have also been updated to fix the following security issues :

- Props to Muaz Bin Abdus Sattar and Jannes who both independently reported an issue where password reset tokens were not properly invalidated

- Props to ka1n4t for finding an issue where certain private posts can be viewed unauthenticated

- Props to Evan Ricafort for discovering an XSS issue in the Customizer

- Props to Ben Bidner from the WordPress Security Team who discovered an XSS issue in the search block

- Props to Nick Daugherty from WordPress VIP / WordPress Security Team who discovered an XSS issue in wp-object-cache

- Props to Ronnie Goodrich (Kahoots) and Jason Medeiros who independently reported an XSS issue in file uploads.

- Props to Weston Ruter for fixing a stored XSS vulnerability in the WordPress customizer.

- Additionally, an authenticated XSS issue in the block editor was discovered by Nguyen the Duc in WordPress 5.4 RC1 and RC2. It was fixed in 5.4 RC5. We wanted to be sure to give credit and thank them for all of their work in making WordPress more secure.

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website.
Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected wordpress package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2020-7701f49327

Plugin Details

Severity: High

ID: 136437

File Name: fedora_2020-7701f49327.nasl

Version: 1.1

Type: local

Agent: unix

Published: 5/11/2020

Updated: 5/11/2020

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:wordpress, cpe:/o:fedoraproject:fedora:31

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 5/9/2020

Vulnerability Publication Date: 5/9/2020

Reference Information