6.4
CVSSv2

CVE-2020-28039

Published: 02/11/2020 Updated: 07/11/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

is_protected_meta in wp-includes/meta.php in WordPress prior to 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress

debian debian linux 9.0

debian debian linux 10.0

canonical ubuntu linux 18.04

canonical ubuntu linux 20.04

canonical ubuntu linux 16.04

Vendor Advisories

Debian Bug report logs - #973562 wordpress: Wordpress 552 security release Package: wordpress; Maintainer for wordpress is Craig Small <csmall@debianorg>; Source for wordpress is src:wordpress (PTS, buildd, popcon) Reported by: Craig Small <csmall@debianorg> Date: Sun, 1 Nov 2020 21:03:02 UTC Severity: importan ...
Several vulnerabilities were discovered in Wordpress, a web blogging tool They allowed remote attackers to run insecure deserialization, embed spam, perform various Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF) attacks, escalate privileges, run arbitrary code, and delete arbitrary files For the stable distribution (buster), thes ...
is_protected_meta in wp-includes/metaphp in WordPress before 552 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected ...