Lucene search

K
patchstackJan LieskovskyPATCHSTACK:EDB052BFE3C6FE6E63A5FBE379175123
HistoryFeb 19, 2013 - 12:00 a.m.

WordPress <= 3.5.1 - External Entity Injection

2013-02-1900:00:00
Jan Lieskovsky
patchstack.com
8

0.004 Low

EPSS

Percentile

72.2%

Because of this vulnerability, the attackers can read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference.

Solution

           Update the plugin. 
CPENameOperatorVersion
wordpressle3.5.1

0.004 Low

EPSS

Percentile

72.2%