Fedora 35 : wordpress (2022-35ce8ecede)

high Nessus Plugin ID 169165

Language:

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora 35 host has a package installed that is affected by a vulnerability as referenced in the FEDORA-2022-35ce8ecede advisory.

- **WordPress 5.9.5 Security Release** Security updates included in this release * Stored XSS via wp- mail.php (post by email) Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc. via JPCERT * Open redirect in `wp_nonce_ays` devrayn * Sender's email address is exposed in wp-mail.php Toshitsugu Yoneyama of Mitsui Bussan Secure Directions, Inc. via JPCERT * Media Library Reflected XSS via SQLi Ben Bidner from the WordPress security team and Marc Montpas from Automattic independently discovered this issue * CSRF in wp-trackback.php Simon Scannell * Stored XSS via the Customizer Alex Concha from the WordPress security team * Revert shared user instances introduced in 50790 Alex Concha and Ben Bidner from the WordPress security team * Stored XSS in WordPress Core via Comment Editing Third-party security audit and Alex Concha from the WordPress security team * Data exposure via the REST Terms/Tags Endpoint Than Taintor * Content from multipart emails leaked Thomas Krftner * SQL Injection due to improper sanitization in `WP_Date_Query` Michael Mazzolini * RSS Widget: Stored XSS issue Third-party security audit * Stored XSS in the search block Alex Concha of the WP Security team * Feature Image Block: XSS issue Third-party security audit * RSS Block:
Stored XSS issue Third-party security audit * Fix widget block XSS Third-party security audit (FEDORA-2022-35ce8ecede)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected wordpress package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2022-35ce8ecede

Plugin Details

Severity: High

ID: 169165

File Name: fedora_2022-35ce8ecede.nasl

Version: 1.0

Type: local

Agent: unix

Published: 12/22/2022

Updated: 12/22/2022

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:35, p-cpe:/a:fedoraproject:fedora:wordpress

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 10/18/2022

Vulnerability Publication Date: 10/18/2022

Reference Information