In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T06:01:49.194Z

Reserved: 2018-01-29T00:00:00

Link: CVE-2018-6389

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-02-06T17:29:00.253

Modified: 2024-11-21T04:10:36.930

Link: CVE-2018-6389

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.