‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. random_savv · · focus · HN ↗
    I am so happy that I asked Codex to rewrite our website as Hugo templates which allowed us to statically host it and get rid of Wordpress. So much stress gone!
    1. vntok · · focus · HN ↗
      Sorry in advance if you were joking, but for readers who aren't in the know: Hugo had, in fact, two 9.3 CVSS vulnerabilities just 11 days ago...

      <a href="https:&#x2F;&#x2F;app.opencve.io&#x2F;cve&#x2F;CVE-2026-89259" rel="nofollow">https:&#x2F;&#x2F;app.opencve.io&#x2F;cve&#x2F;CVE-2026-89259

      <a href="https:&#x2F;&#x2F;app.opencve.io&#x2F;cve&#x2F;CVE-2026-89258" rel="nofollow">https:&#x2F;&#x2F;app.opencve.io&#x2F;cve&#x2F;CVE-2026-89258

      1. benregenspan · · focus · HN ↗
        This seems like a really good example of Base CVSS scores not telling us much on their own.

        For the Wordpress RCE (nominally CVSS 9.2), it looks like many standard deployments of WordPress would be affected, barring extra mitigations. But in the case of these Hugo ones (9.3), it looks like very specific circumstances (anti-mitigations, if you will) are needed. E.g. running arbitrary builds of untrusted user content without a sandbox; running it in a GitHub workflow against PRs from untrusted contributors, etc.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.