‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. beezle · · focus · HN ↗
    "WordPress 7.1.2 has been released containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7"

    As a courtesy, I try not to say more than one bad thing about WP every day. FWIW about 1/3 of installs are not on the recent 7 branch.

    1. jeroenhd · · focus · HN ↗
      WordPress doesn't to LTS. WordPress usually backports security fixes to older branches (like the 6.x branches) but going all the way back to 4.x isn't something they'll do for every fix. Who knows how many bugs lie in wait for older versions that are out of support.

      If you run WordPress, you should be aware of this already. Either upgrade to the latest versions, constantly and quickly, or have extremely restrictive WAFs up and ready. Especially if you have any plugins installed (as those are usually where the WordPress exploits are coming from).

      I'd recommend everyone unhappy only finding out about WordPress' long-standing support policy to ask their money back.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.