CVE-2018-6389: High severity WordPress vulnerability
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6389?
CVE-2018-6389 is categorized as a denial of service vulnerability, caused by unauthenticated attackers due to resource consumption.
How do I fix CVE-2018-6389?
To mitigate CVE-2018-6389, update your WordPress installation to a version later than 4.9.2.
Who is affected by CVE-2018-6389?
CVE-2018-6389 affects unprotected installations of WordPress versions up to 4.9.2.
What type of attack does CVE-2018-6389 involve?
CVE-2018-6389 involves a denial of service attack that consumes server resources by repeatedly loading registered .js files.
Can CVE-2018-6389 be exploited remotely?
Yes, attackers can exploit CVE-2018-6389 remotely without authentication.