Information Exposure Affecting johnpbloch/wordpress package, versions >=5.1, <5.1.6>=5.2, <5.2.7>=5.3, <5.3.4>=5.4, <5.4.2


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.09% (41st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-JOHNPBLOCHWORDPRESS-674449
  • published14 Sept 2020
  • disclosed14 Sept 2020
  • creditUnknown

Introduced: 14 Sep 2020

CVE-2020-25286  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade johnpbloch/wordpress to version 5.1.6, 5.2.7, 5.3.4, 5.4.2 or higher.

Overview

johnpbloch/wordpress is a software you can use to create a beautiful website, blog, or app.

Affected versions of this package are vulnerable to Information Exposure. In wp-includes/comment-template.php, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.

References

CVSS Scores

version 3.1