Lucene search

K
wpvulndbWpvulndbWPVDB-ID:016774DF-5031-4315-A893-A47D99273883
HistoryOct 29, 2020 - 12:00 a.m.

WordPress < 5.5.2 - Unauthenticated DoS Attack to RCE

2020-10-2900:00:00
wpscan.com
312
wordpress
version 5.5.2
unauthenticated
dos attack
rce
mysql database
installation wizard
original researcher
vulnerability.

EPSS

0.022

Percentile

89.7%

The release notes state: “Props to Omar Ganiev who reported a method where a DoS attack could lead to RCE.” The attack consisted of creating a DoS condition on the MySQL database, which would make WordPress think that it has not been installed, presenting the installation wizard. The DoS attack would then need to be stopped. According the original researcher, the attack would be very hard to reproduce.

EPSS

0.022

Percentile

89.7%