CVE-2018-20148: Critical severity wordpress vulnerability
Published Dec 14, 2018
·Updated
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wpgetattachmentthumbfile function in wp-includes/post.php.
Affected Software
5 affected componentsFixes available
debian/wordpress
5.0.15+dfsg1-0+deb10u15.0.19+dfsg1-0+deb10u15.7.8+dfsg1-0+deb11u26.1.1+dfsg1-16.3.1+dfsg1-1
WordPress WordPress<4.9.9
WordPress WordPress>=5.0<5.0.1
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Event History
Dec 14, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20148?
CVE-2018-20148 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2018-20148?
To fix CVE-2018-20148, update WordPress to version 5.0.1 or later.
3
Which versions of WordPress are affected by CVE-2018-20148?
CVE-2018-20148 affects WordPress versions prior to 4.9.9 and from 5.0 to 5.0.1.
4
What types of attacks are possible due to CVE-2018-20148?
CVE-2018-20148 allows for PHP object injection attacks through crafted metadata in XMLRPC calls.
5
What component of WordPress is vulnerable in CVE-2018-20148?
The vulnerability in CVE-2018-20148 is related to the wp_get_attachment_thumb_file function in wp-includes/post.php.