WordPress 5.1 CSRF to Remote Code Execution

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

Last month we released an authenticated remote code execution (RCE) vulnerability in WordPress 5.0. This blog post reveals another critical exploit chain for WordPress 5.1 that enables an unauthenticated attacker to gain remote code execution on any WordPress installation prior to version 5.1.1. ### Impact An attacker can take over any WordPress site that has comments enabled by tricking an administrator of a target blog to visit a website set up by the attacker. As soon as the victim administrator visits the malicious website, a cross-site request forgery (CSRF) exploit is run against the target WordPress blog in the background, without the victim noticing. The CSRF exploit abuses multiple logic flaws and sanitization errors that when combined lead to Remote Code Execution and a full site takeover. The vulnerabilities exist in WordPress versions prior to 5.1.1 and is exploitable with default settings. WordPress is used by over 33% of all websites on the internet, according to its...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息