In affected versions of WordPress, files with a specially crafted name when uploaded to the Media section can lead to script execution upon accessing the file. This requires an authenticated user with privileges to upload files. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2020-04-30T22:15:32
Updated: 2024-08-04T11:21:14.284Z
Reserved: 2020-03-30T00:00:00
Link: CVE-2020-11026
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-04-30T23:15:11.510
Modified: 2024-11-21T04:56:37.070
Link: CVE-2020-11026
Redhat
No data.