CVE-2020-28037: Critical severity wordpress vulnerability
Published Oct 31, 2020
·Updated
isbloginstalled in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).
Affected Software
6 affected componentsFixes available
debian/wordpress
5.0.15+dfsg1-0+deb10u15.0.19+dfsg1-0+deb10u15.7.8+dfsg1-0+deb11u26.1.1+dfsg1-16.3.1+dfsg1-1
WordPress WordPress<5.5.2
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Fedoraproject Fedora=33
Debian Debian Linux=10.0
Remediation
Event History
Oct 31, 2020
CVE Published
via MITRE·12:59 AM
Data Sourced
via MITRE·12:59 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this WordPress vulnerability?
The vulnerability ID for this WordPress vulnerability is CVE-2020-28037.
2
What is the severity of CVE-2020-28037?
The severity of CVE-2020-28037 is critical.
3
How does CVE-2020-28037 affect WordPress?
CVE-2020-28037 allows an attacker to perform a new installation of WordPress, leading to remote code execution and a denial of service for the old installation.
4
Which versions of WordPress are affected by CVE-2020-28037?
Versions before 5.5.2 of WordPress are affected by CVE-2020-28037.
5
How can I fix the vulnerability CVE-2020-28037 in WordPress?
To fix the vulnerability CVE-2020-28037 in WordPress, update to version 5.5.2 or later.