Back to search
CVE-2019-8942
Published: Feb 20, 2019
Modified: Aug 4, 2024
PUBLISHED
Description
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://wpvulndb.com/vulnerabilities/9222
x_refsource_MISC
46511
exploit
x_refsource_EXPLOIT-DB
107088
vdb-entry
x_refsource_BID
DSA-4401
vendor-advisory
x_refsource_DEBIAN
[debian-lts-announce] 20190331 [SECURITY] [DLA 1742-1] wordpress security update
mailing-list
x_refsource_MLIST
http://www.rapid7.com/db/modules/exploit/multi/http/wp_crop_rce
x_refsource_MISC
46662
exploit
x_refsource_EXPLOIT-DB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now