CVE-2008-6767: Critical severity wordpress vulnerability
Published Apr 28, 2009
·Updated
wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.
Affected Software
1 affected component
WordPress=2.6
Event History
Apr 28, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-6767?
CVE-2008-6767 is considered to potentially lead to application outages, making it a critical vulnerability.
2
How do I fix CVE-2008-6767?
To fix CVE-2008-6767, upgrade your WordPress installation from version 2.6.x to a more secure version.
3
Who is affected by CVE-2008-6767?
CVE-2008-6767 affects users running WordPress version 2.6 and below.
4
Can CVE-2008-6767 lead to data loss?
CVE-2008-6767 may not directly cause data loss but can lead to denial of service that affects application availability.
5
What type of attack does CVE-2008-6767 enable?
CVE-2008-6767 enables remote attackers to potentially exploit the application through unauthorized upgrades.