Improper input validation in WordPress - CVE-2019-17675
Published: October 15, 2019 / Updated: October 30, 2019
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input passed via the referred header in the admin panel. A remote attacker can trick a victim to visit a specially crafted webpage and bypass implemented security restrictions that rely on HTTP referrer header.
Affected software
wordpress (Debian package)
How to mitigate CVE-2019-17675
wordpress (Debian package) - addressed in versions 4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1