CVE-2019-9787
HIGH 8.8EPSS 38.7%
WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search Engine Optimization of A elements is performed incorrectly, leading to XSS. The XSS results in administrative access, which allows arbitrary changes to .php files. This is related to wp-admin/includes/ajax-actions.php and wp-includes/comment.php.
- CVSS v3.0
- 8.8 HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 38.70% chance of exploitation in the next 30 days, 98th percentile
- Nuclei
- medium
- Published
- 2019-03-14
- Updated
- 2024-08-04
Proof-of-concept exploits (4)
- PalmTreeForest/CodePath_Week_7-80★ · 2019-08-18
- dexXxed/CVE-2019-97870★ · 2021-06-29
- matinciel/Wordpress_CVE-2019-97870★ · 2020-07-02
- rkatogit/cve-2019-9787_csrf_poc2★ · 2019-04-15