‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. tptacek · · focus · HN ↗
    These CVSS scores don't mean anything and it would be better for everyone if they stopped showing up in headlines. This is a somewhat situational Wordpress RCE that impacts only a couple themes.
    1. paulez · · focus · HN ↗
      This score specifically means that given some specific conditions, anyone can execute code over the network on a vulnerable WordPress setup. Is this not true?
      1. bombcar · · focus · HN ↗
        My assumption is that any Wordpress setup whatsoever allows anyone to execute code remotely.
        1. 6c696e7578 · · focus · HN ↗
          Indeed, it's a foothold into a network.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.