WordPress <= 5.0 - PHP Object Injection via Meta Data



Description
According to WordPress:

"Sam Thomas discovered that contributors could craft meta data in a way that resulted in PHP object injection."

Affects WordPresses

fixed in version 5.0.1
fixed in version 4.9.9
fixed in version 4.9.9
fixed in version 4.9.9
fixed in version 4.9.9
fixed in version 4.9.9
fixed in version 4.9.9
fixed in version 4.9.9
fixed in version 4.9.9
fixed in version 4.9.9
fixed in version 4.8.8
fixed in version 4.8.8
fixed in version 4.8.8
fixed in version 4.8.8
fixed in version 4.8.8
fixed in version 4.8.8
fixed in version 4.8.8
fixed in version 4.8.8
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28

References

CVE 2018-20148
URL https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/

Classification

Type OBJECTINJECTION
OWASP Top 10 A8: Insecure Deserialization
CWE CWE-502

Miscellaneous

Original Researcher Sam Thomas
Submitter Ryan Dewhurst
Submitter Website https://dewhurstsecurity.com/
Submitter Twitter ethicalhack3r
Views 30292
Verified No
WPVDB ID 9171

Timeline

Publicly Published 2018-12-13 (11 months ago)
Added 2018-12-13 (11 months ago)
Last Updated 2019-11-01 (13 days ago)

Our Other Services

Online WordPress Vulnerability Scanner WPScan WordPress Security Plugin