Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-4050


In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged by low privileged users. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18, 4.6.19, 4.5.22, 4.4.23, 4.3.24, 4.2.28, 4.1.31, 4.0.31, 3.9.32, 3.8.34, 3.7.34).


Published

2020-06-12T16:15:10.793

Last Modified

2024-11-21T05:32:13.540

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.5 (LOW)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

6.8

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-288

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application wordpress wordpress < 3.7.34 Yes
Application wordpress wordpress < 3.8.34 Yes
Application wordpress wordpress < 3.9.32 Yes
Application wordpress wordpress < 4.0.31 Yes
Application wordpress wordpress < 4.1.31 Yes
Application wordpress wordpress < 4.2.28 Yes
Application wordpress wordpress < 4.3.24 Yes
Application wordpress wordpress < 4.4.23 Yes
Application wordpress wordpress < 4.5.22 Yes
Application wordpress wordpress < 4.6.19 Yes
Application wordpress wordpress < 4.7.18 Yes
Application wordpress wordpress < 4.8.14 Yes
Application wordpress wordpress < 4.9.15 Yes
Application wordpress wordpress < 5.0.10 Yes
Application wordpress wordpress < 5.1.6 Yes
Application wordpress wordpress < 5.2.7 Yes
Application wordpress wordpress < 5.3.4 Yes
Application wordpress wordpress < 5.4.2 Yes
Operating System fedoraproject fedora 31 Yes
Operating System fedoraproject fedora 32 Yes
Operating System debian debian_linux 8.0 Yes
Operating System debian debian_linux 9.0 Yes
Operating System debian debian_linux 10.0 Yes

References