CVE-2020-28033: High severity wordpress vulnerability
Published Oct 31, 2020
·Updated
WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.
Affected Software
7 affected componentsFixes available
debian/wordpress
5.0.15+dfsg1-0+deb10u15.0.19+dfsg1-0+deb10u15.7.8+dfsg1-0+deb11u26.1.1+dfsg1-16.3.1+dfsg1-1
WordPress WordPress<5.5.2
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Event History
Oct 31, 2020
CVE Published
via MITRE·12:59 AM
Data Sourced
via MITRE·12:59 AM
Description
Frequently Asked Questions
1
What is CVE-2020-28033?
CVE-2020-28033 is a vulnerability in WordPress before version 5.5.2 that mishandles embeds from disabled sites on a multisite network, allowing a spam embed.
2
How does CVE-2020-28033 affect WordPress?
CVE-2020-28033 affects WordPress versions before 5.5.2.
3
What is the severity of CVE-2020-28033?
The severity of CVE-2020-28033 is high with a CVSS score of 7.5.
4
How can I fix CVE-2020-28033?
To fix CVE-2020-28033, you should update your WordPress installation to version 5.5.2 or higher.
5
Where can I find more information about CVE-2020-28033?
You can find more information about CVE-2020-28033 on the official WordPress website and the Debian security tracker.