Описание
WordPress is an open publishing platform for the Web. Unserialization of instances of the WP_HTML_Token class allows for code execution via its __destruct() magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.
Уязвимые конфигурации
Конфигурация 1Версия от 6.4.0 (включая) до 6.4.2 (исключая)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
EPSS
Процентиль: 84%
0.0274
Низкий
5.5 Medium
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-502
Связанные уязвимости
CVSS3: 5.5
ubuntu
больше 2 лет назад
WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.
CVSS3: 5.5
debian
больше 2 лет назад
WordPress is an open publishing platform for the Web. Unserialization ...
EPSS
Процентиль: 84%
0.0274
Низкий
5.5 Medium
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-502