Junglewise Threat Intelligence

CVE-2017-5488: WordPress XSS in update-core.php via plugin headers

CVE-2017-5488 · Severity: medium · CVSS 6.1 · Published 2017-01-15

Technologies: Wordpress. Vendors: Wordpress.

Executive brief

WordPress, a popular website management and blogging platform, is vulnerable to a security flaw in its core update component. This vulnerability allows an attacker to inject malicious scripts into the administrative dashboard by tricking a site administrator into viewing a page with specially crafted plugin information. If exploited, this could lead to unauthorized actions being performed on the website or the theft of administrative session data.

Technical details

Multiple stored cross-site scripting (XSS) vulnerabilities exist in the 'wp-admin/update-core.php' component of WordPress versions prior to 4.7.1. The root cause is the improper neutralization of input within the 'name' and 'version' headers of plugin files when they are processed and displayed on the core update screen. An attacker can exploit this by providing a malicious plugin (or a plugin update) containing crafted headers. When an administrator visits the update page, the malicious script executes in the context of their browser session. This can lead to session hijacking, unauthorized administrative actions, or further site compromise. The issue was addressed in version 4.7.1 by ensuring plugin data is properly translated and escaped before rendering.

Affected products

  • WordPress WordPress < 4.7.1

Timeline

  • 2017-01-11: patched: WordPress 4.7.1 released
  • 2017-01-14: disclosed: Public disclosure via oss-security mailing list
  • 2017-01-15: advisory: NVD publication date

References

Related threats