#VU14439 Insecure deserialization in WordPress - CVE-2017-1000600,CVE-2018-1000773
Published: August 17, 2018 / Updated: November 1, 2020
WordPress
WordPress.ORG
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insecure deserialization of data passed as an image file and then executed via the "phar://" stream wrapper within the "wp_get_attachment_thumb_file" function in "/wpincludes/post.php" script. A remote authenticated attacker with ability to create/edit posts can upload a malicious image and execute arbitrary PHP code on vulnerable system.