First published: Thu Sep 09 2021(Updated: )
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like nonces. It can then be used to perform actions on your behalf. This has been patched in WordPress 5.8.1, along with any older affected versions via minor releases. It's strongly recommended that you keep auto-updates enabled to receive the fix.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/wordpress | 5.0.15+dfsg1-0+deb10u1 5.0.19+dfsg1-0+deb10u1 5.7.8+dfsg1-0+deb11u2 6.1.1+dfsg1-1 6.3.1+dfsg1-1 | |
WordPress WordPress | >=5.2<5.8.1 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39200 is a vulnerability in WordPress that allows for leakage of data under certain conditions.
The severity of CVE-2021-39200 is high with a CVSS score of 5.3.
CVE-2021-39200 affects output data of the function wp_die() in certain versions of WordPress.
WordPress versions 5.0.15, 5.0.19, 5.7.8, 6.1.1, and 6.3.1 are affected by CVE-2021-39200.
To fix CVE-2021-39200, update WordPress to a version that is not affected by the vulnerability.