WordPress <= 5.2.3 - Hardening Bypass

Affects WordPresses

fixed in version 5.2.4
fixed in version 5.2.4
fixed in version 5.2.4
fixed in version 5.2.4
fixed in version 5.1.3
fixed in version 5.1.3
fixed in version 5.1.3
fixed in version 5.0.7
fixed in version 5.0.7
fixed in version 5.0.7
fixed in version 5.0.7
fixed in version 5.0.7
fixed in version 5.0.7
fixed in version 4.9.12
fixed in version 4.9.12
fixed in version 4.9.12
fixed in version 4.9.12
fixed in version 4.8.11
fixed in version 4.8.11
fixed in version 4.8.11
fixed in version 4.7.15
fixed in version 4.7.15
fixed in version 4.7.15
fixed in version 4.7.15
fixed in version 4.7.15
fixed in version 4.7.15
fixed in version 4.7.15
fixed in version 4.6.16
fixed in version 4.6.16
fixed in version 4.6.16
fixed in version 4.6.16
fixed in version 4.6.16
fixed in version 4.6.16
fixed in version 4.6.16
fixed in version 4.6.16
fixed in version 4.5.19
fixed in version 4.5.19
fixed in version 4.5.19
fixed in version 4.5.19
fixed in version 4.5.19
fixed in version 4.5.19
fixed in version 4.5.19
fixed in version 4.5.19
fixed in version 4.5.19
fixed in version 4.5.19
fixed in version 4.5.19
fixed in version 4.4.20
fixed in version 4.4.20
fixed in version 4.4.20
fixed in version 4.4.20
fixed in version 4.4.20
fixed in version 4.4.20
fixed in version 4.4.20
fixed in version 4.4.20
fixed in version 4.4.20
fixed in version 4.4.20
fixed in version 4.4.20
fixed in version 4.4.20
fixed in version 4.4.20
fixed in version 4.3.21
fixed in version 4.3.21
fixed in version 4.3.21
fixed in version 4.3.21
fixed in version 4.3.21
fixed in version 4.3.21
fixed in version 4.3.21
fixed in version 4.3.21
fixed in version 4.3.21
fixed in version 4.3.21
fixed in version 4.3.21
fixed in version 4.3.21
fixed in version 4.3.21
fixed in version 4.3.21
fixed in version 4.2.25
fixed in version 4.2.25
fixed in version 4.2.25
fixed in version 4.2.25
fixed in version 4.2.25
fixed in version 4.2.25
fixed in version 4.2.25
fixed in version 4.2.25
fixed in version 4.2.25
fixed in version 4.2.25
fixed in version 4.2.25
fixed in version 4.2.25
fixed in version 4.2.25
fixed in version 4.2.25
fixed in version 4.2.25
fixed in version 4.2.25
fixed in version 4.2.25
fixed in version 4.2.25
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.1.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 4.0.28
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.9.29
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.8.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31
fixed in version 3.7.31

References

URL https://blog.ripstech.com/2020/wordpress-hardening-bypass/
URL https://hackerone.com/reports/436928
URL https://wordpress.org/news/2019/11/wordpress-5-2-4-update/

Classification

Type BYPASS

Miscellaneous

Original Researcher Simon Scannell
Views 613
Verified No
WPVDB ID 10259

Timeline

Publicly Published 2020-01-21 (5 months ago)
Added 2020-06-09 (24 days ago)
Last Updated 2020-06-10 (24 days ago)

Our Other Services

Online WordPress Vulnerability Scanner WPScan WordPress Security Plugin