Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40586
HistoryMay 18, 2023 - 8:40 a.m.

Directory Traversal

2023-05-1808:40:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
461
wordpress
directory traversal
vulnerability
unauthenticated access
arbitrary scripts
file access restrictions
determine_locale function
wp_lang parameter

0.003 Low

EPSS

Percentile

69.9%

johnpbloch/wordpress-core is vulnerable to Directory Traversal. The vulnerability exists in the determine_locale function via wp_lang parameter due to lack of file access restrictions which allows an unauthenticated attacker to access and load arbitrary translation files and to inject and execute arbitrary scripts.