5
CVSSv2

CVE-2017-14719

Published: 23/09/2017 Updated: 10/11/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress 4.7.1

wordpress wordpress 4.7.2

wordpress wordpress 4.6.6

wordpress wordpress 4.6.5

wordpress wordpress 4.6.4

wordpress wordpress 4.5.7

wordpress wordpress 4.5.6

wordpress wordpress 4.5

wordpress wordpress 4.4.9

wordpress wordpress 4.4.11

wordpress wordpress 4.4.10

wordpress wordpress 4.3.5

wordpress wordpress 4.3.4

wordpress wordpress 4.3

wordpress wordpress 4.2.9

wordpress wordpress 4.2.16

wordpress wordpress 4.2.15

wordpress wordpress 4.2

wordpress wordpress 4.1.9

wordpress wordpress 4.1.2

wordpress wordpress 4.1.19

wordpress wordpress 4.1.11

wordpress wordpress 4.1.10

wordpress wordpress 4.0.5

wordpress wordpress 4.0.4

wordpress wordpress 4.0.15

wordpress wordpress 4.0.14

wordpress wordpress 3.9.8

wordpress wordpress 3.9.7

wordpress wordpress 3.9.19

wordpress wordpress 3.9.18

wordpress wordpress 3.9.11

wordpress wordpress 3.9.10

wordpress wordpress 3.9.1

wordpress wordpress 3.8.4

wordpress wordpress 3.8.3

wordpress wordpress 3.8.17

wordpress wordpress 3.8.16

wordpress wordpress 3.8.1

wordpress wordpress 3.8

wordpress wordpress 4.7

wordpress wordpress 4.8.1

wordpress wordpress 4.6.7

wordpress wordpress 4.5.9

wordpress wordpress 4.5.8

wordpress wordpress 4.5.10

wordpress wordpress 4.5.1

wordpress wordpress 4.4.4

wordpress wordpress 4.4.3

wordpress wordpress 4.4.2

wordpress wordpress 4.3.7

wordpress wordpress 4.3.6

wordpress wordpress 4.3.10

wordpress wordpress 4.3.1

wordpress wordpress 4.2.4

wordpress wordpress 4.2.3

wordpress wordpress 4.2.2

wordpress wordpress 4.2.10

wordpress wordpress 4.2.1

wordpress wordpress 4.1.4

wordpress wordpress 4.1.3

wordpress wordpress 4.1.13

wordpress wordpress 4.1.12

wordpress wordpress 4.0.7

wordpress wordpress 4.0.6

wordpress wordpress 4.0.17

wordpress wordpress 4.0.16

wordpress wordpress 4.0

wordpress wordpress 3.9.9

wordpress wordpress 3.9.20

wordpress wordpress 3.9.2

wordpress wordpress 3.9.13

wordpress wordpress 3.9.12

wordpress wordpress 3.8.6

wordpress wordpress 3.8.5

wordpress wordpress 3.8.19

wordpress wordpress 4.7.5

wordpress wordpress 4.8

wordpress wordpress 4.6.1

wordpress wordpress 4.6

wordpress wordpress 4.5.3

wordpress wordpress 4.5.2

wordpress wordpress 4.4.6

wordpress wordpress 4.4.5

wordpress wordpress 4.3.9

wordpress wordpress 4.3.8

wordpress wordpress 4.3.12

wordpress wordpress 4.3.11

wordpress wordpress 4.2.6

wordpress wordpress 4.2.5

wordpress wordpress 4.2.12

wordpress wordpress 4.2.11

wordpress wordpress 4.1.6

wordpress wordpress 4.1.5

wordpress wordpress 4.1.16

wordpress wordpress 4.1.15

wordpress wordpress 4.1.14

wordpress wordpress 4.0.9

wordpress wordpress 4.0.8

wordpress wordpress 4.0.19

wordpress wordpress 4.0.18

wordpress wordpress 4.0.10

wordpress wordpress 4.0.1

wordpress wordpress 3.9.4

wordpress wordpress 3.9.3

wordpress wordpress 3.9.15

wordpress wordpress 3.9.14

wordpress wordpress 3.8.8

wordpress wordpress 3.8.7

wordpress wordpress 3.8.20

wordpress wordpress 3.8.2

wordpress wordpress 3.8.13

wordpress wordpress 3.8.12

wordpress wordpress 3.7.6

wordpress wordpress 3.7.5

wordpress wordpress 3.7.19

wordpress wordpress 3.7.18

wordpress wordpress 3.7.11

wordpress wordpress 3.7.10

wordpress wordpress 3.4.2

wordpress wordpress 3.4.1

wordpress wordpress 3.2

wordpress wordpress 3.1.4

wordpress wordpress 3.0.4

wordpress wordpress 3.0.3

wordpress wordpress 3.8.18

wordpress wordpress 3.8.11

wordpress wordpress 3.8.10

wordpress wordpress 3.7.4

wordpress wordpress 3.7.3

wordpress wordpress 3.7.17

wordpress wordpress 3.7.16

wordpress wordpress 3.7.1

wordpress wordpress 3.7

wordpress wordpress 3.6.1

wordpress wordpress 3.4

wordpress wordpress 3.3.3

wordpress wordpress 3.1.3

wordpress wordpress 3.1.2

wordpress wordpress 3.0.1

wordpress wordpress 3.0

wordpress wordpress 3.0.2

wordpress wordpress 3.7.9

wordpress wordpress 3.7.22

wordpress wordpress 3.7.21

wordpress wordpress 3.7.15

wordpress wordpress 3.7.14

wordpress wordpress 3.6

wordpress wordpress 3.5.2

wordpress wordpress 3.3.2

wordpress wordpress 3.3.1

wordpress wordpress 3.1.1

wordpress wordpress 3.1

wordpress wordpress 4.7.3

wordpress wordpress 4.7.4

wordpress wordpress 4.6.3

wordpress wordpress 4.6.2

wordpress wordpress 4.5.5

wordpress wordpress 4.5.4

wordpress wordpress 4.4.8

wordpress wordpress 4.4.7

wordpress wordpress 4.4.1

wordpress wordpress 4.4

wordpress wordpress 4.3.3

wordpress wordpress 4.3.2

wordpress wordpress 4.2.8

wordpress wordpress 4.2.7

wordpress wordpress 4.2.14

wordpress wordpress 4.2.13

wordpress wordpress 4.1.8

wordpress wordpress 4.1.7

wordpress wordpress 4.1.18

wordpress wordpress 4.1.17

wordpress wordpress 4.1.1

wordpress wordpress 4.1

wordpress wordpress 4.0.3

wordpress wordpress 4.0.2

wordpress wordpress 4.0.13

wordpress wordpress 4.0.12

wordpress wordpress 4.0.11

wordpress wordpress 3.9.6

wordpress wordpress 3.9.5

wordpress wordpress 3.9.17

wordpress wordpress 3.9.16

wordpress wordpress 3.9

wordpress wordpress 3.8.9

wordpress wordpress 3.8.22

wordpress wordpress 3.8.21

wordpress wordpress 3.8.15

wordpress wordpress 3.8.14

wordpress wordpress 3.7.8

wordpress wordpress 3.7.7

wordpress wordpress 3.7.20

wordpress wordpress 3.7.2

wordpress wordpress 3.7.13

wordpress wordpress 3.7.12

wordpress wordpress 3.5.1

wordpress wordpress 3.5

wordpress wordpress 3.3

wordpress wordpress 3.2.1

wordpress wordpress 3.0.6

wordpress wordpress 3.0.5

Vendor Advisories

Debian Bug report logs - #877629 wordpress: CVE-2017-14990 Package: src:wordpress; Maintainer for src:wordpress is Craig Small <csmall@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 3 Oct 2017 15:21:02 UTC Severity: important Tags: security, upstream Found in version wordpress/482+d ...
Debian Bug report logs - #876274 wordpress: 9 security bugs in wordpress 481 and earlier Package: src:wordpress; Maintainer for src:wordpress is Craig Small <csmall@debianorg>; Reported by: Craig Small <csmall@debianorg> Date: Wed, 20 Sep 2017 12:24:01 UTC Severity: grave Tags: security, upstream Found in versio ...
Several vulnerabilities were discovered in Wordpress, a web blogging tool They would allow remote attackers to exploit path-traversal issues, perform SQL injections and various cross-site scripting attacks For the oldstable distribution (jessie), these problems have been fixed in version 41+dfsg-1+deb8u15 For the stable distribution (stretch), ...

Github Repositories

CodePath Assignment for Weeks 7 & 8: CVE-2017-14719, CVE-2019-9787 & Unauthenticated Page/Post Content Modification via REST API

CodePath Week 7-8 CodePath Assignment for Weeks 7 & 8: CVE-2017-14719, CVE-2019-9787 & Unauthenticated Page/Post Content Modification via REST API Project 7 - WordPress Pentesting Time spent: 16 hours spent in total Objective: Find, analyze, recreate, and document vulnerabilities affecting an old version of WordPress Pentesting Report 1 CVE-2017-14719 Summa

Project 7 - WordPress Pentesting Time spent: 24 hours spent in total Objective: Find, analyze, recreate, and document 3 vulnerabilities affecting an old version of WordPress Pentesting Report 1 CVE-2017-9061 Summary: XSS via Large File Upload Error Vulnerability types: XSS Injection Tested in version: 420 Fixed in version: 4215 GIF Walkthrough: Found in file_size_