CVE-2020-28036: Critical severity wordpress vulnerability
Published Oct 31, 2020
·Updated
wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.
Affected Software
6 affected componentsFixes available
debian/wordpress
5.0.15+dfsg1-0+deb10u15.0.19+dfsg1-0+deb10u15.7.8+dfsg1-0+deb11u26.1.1+dfsg1-16.3.1+dfsg1-1
WordPress WordPress<5.5.2
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Debian Debian Linux=10.0
Remediation
Event History
Oct 31, 2020
CVE Published
via MITRE·12:59 AM
Data Sourced
via MITRE·12:59 AM
Description
Frequently Asked Questions
1
What is CVE-2020-28036?
CVE-2020-28036 is a vulnerability in WordPress before version 5.5.2 that allows attackers to gain privileges by using XML-RPC to comment on a post.
2
How severe is CVE-2020-28036?
CVE-2020-28036 has a severity value of 9.8, which is considered critical.
3
How can an attacker exploit CVE-2020-28036?
An attacker can exploit CVE-2020-28036 by using XML-RPC to comment on a post, gaining privileges and potentially compromising the WordPress site.
4
What is the remedy for CVE-2020-28036?
To fix CVE-2020-28036, WordPress sites should be updated to version 5.5.2 or higher, which addresses the vulnerability.
5
Where can I find more information about CVE-2020-28036?
More information about CVE-2020-28036 can be found on the WordPress official website and the GitHub commit page.