Vulnerability Description
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wordpress | Wordpress | < 5.2.4 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- https://blog.wpscan.org/wordpress/security/release/2019/10/15/wordpress-524-secuThird Party Advisory
- https://core.trac.wordpress.org/changeset/46477PatchVendor Advisory
- https://github.com/WordPress/WordPress/commit/b183fd1cca0b44a92f0264823dd9f22d2fPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/11/msg00000.htmlMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2020/Jan/8Mailing ListThird Party Advisory
- https://wordpress.org/news/2019/10/wordpress-5-2-4-security-release/Release NotesVendor Advisory
- https://wpvulndb.com/vulnerabilities/9913Release NotesThird Party Advisory
- https://www.debian.org/security/2020/dsa-4599Third Party Advisory
- https://www.debian.org/security/2020/dsa-4677Third Party Advisory
- https://blog.wpscan.org/wordpress/security/release/2019/10/15/wordpress-524-secuThird Party Advisory
- https://core.trac.wordpress.org/changeset/46477PatchVendor Advisory
- https://github.com/WordPress/WordPress/commit/b183fd1cca0b44a92f0264823dd9f22d2fPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/11/msg00000.htmlMailing ListThird Party Advisory
- https://seclists.org/bugtraq/2020/Jan/8Mailing ListThird Party Advisory
- https://wordpress.org/news/2019/10/wordpress-5-2-4-security-release/Release NotesVendor Advisory
FAQ
What is CVE-2019-17675?
CVE-2019-17675 is a vulnerability with a CVSS score of 8.8 (HIGH). WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
How severe is CVE-2019-17675?
CVE-2019-17675 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-17675?
Check the references section above for vendor advisories and patch information. Affected products include: Wordpress Wordpress, Debian Debian Linux.