Описание
WordPress is an open publishing platform for the Web. Unserialization of instances of the WP_HTML_Token class allows for code execution via its __destruct() magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.
Уязвимые конфигурации
Конфигурация 1Версия от 6.4.0 (включая) до 6.4.2 (исключая)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
EPSS
Процентиль: 97%
0.44881
Средний
5.5 Medium
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-502
Связанные уязвимости
CVSS3: 5.5
ubuntu
почти 2 года назад
WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.
CVSS3: 5.5
debian
почти 2 года назад
WordPress is an open publishing platform for the Web. Unserialization ...
EPSS
Процентиль: 97%
0.44881
Средний
5.5 Medium
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-502