DSA-4677-1 wordpress -- security update

Related Vulnerabilities: CVE-2019-9787   CVE-2019-16217   CVE-2019-16218   CVE-2019-16219   CVE-2019-16220   CVE-2019-16221   CVE-2019-16222   CVE-2019-16223   CVE-2019-16780   CVE-2019-16781   CVE-2019-17669   CVE-2019-17671   CVE-2019-17672   CVE-2019-17673   CVE-2019-17674   CVE-2019-17675   CVE-2019-20041   CVE-2019-20042   CVE-2019-20043   CVE-2020-11025   CVE-2020-11026   CVE-2020-11027   CVE-2020-11028   CVE-2020-11029   CVE-2020-11030  

Several vulnerabilities were discovered in Wordpress, a web blogging tool. They allowed remote attackers to perform various Cross-Side Scripting (XSS) and Cross-Site Request Forgery (CSRF) attacks, create files on the server, disclose private information, create open redirects, poison cache, and bypass authorization access and input sanitation. For the oldstable distribution (stretch), these problems have been fixed in version 4.7.5+dfsg-2+deb9u6. For the stable distribution (buster), these problems have been fixed in version 5.0.4+dfsg1-1+deb10u2. We recommend that you upgrade your wordpress packages. For the detailed security status of wordpress please refer to its security tracker page at: https://security-tracker.debian.org/tracker/wordpress

Debian Security Advisory

DSA-4677-1 wordpress -- security update

Date Reported:
06 May 2020
Affected Packages:
wordpress
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 924546, Bug 939543, Bug 942459, Bug 946905, Bug 959391.
In Mitre's CVE dictionary: CVE-2019-9787, CVE-2019-16217, CVE-2019-16218, CVE-2019-16219, CVE-2019-16220, CVE-2019-16221, CVE-2019-16222, CVE-2019-16223, CVE-2019-16780, CVE-2019-16781, CVE-2019-17669, CVE-2019-17671, CVE-2019-17672, CVE-2019-17673, CVE-2019-17674, CVE-2019-17675, CVE-2019-20041, CVE-2019-20042, CVE-2019-20043, CVE-2020-11025, CVE-2020-11026, CVE-2020-11027, CVE-2020-11028, CVE-2020-11029, CVE-2020-11030.
More information:

Several vulnerabilities were discovered in Wordpress, a web blogging tool. They allowed remote attackers to perform various Cross-Side Scripting (XSS) and Cross-Site Request Forgery (CSRF) attacks, create files on the server, disclose private information, create open redirects, poison cache, and bypass authorization access and input sanitation.

For the oldstable distribution (stretch), these problems have been fixed in version 4.7.5+dfsg-2+deb9u6.

For the stable distribution (buster), these problems have been fixed in version 5.0.4+dfsg1-1+deb10u2.

We recommend that you upgrade your wordpress packages.

For the detailed security status of wordpress please refer to its security tracker page at: https://security-tracker.debian.org/tracker/wordpress