CVE-2020-28039

Published

Severity

CVSS v3:
9.1 CRITICAL
CVSS v2:
6.4 MEDIUM

Description

is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*n/a5.5.2*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*n/an/a9.0
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*n/an/a10.0
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*n/an/a18.04
cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*n/an/a20.04
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*n/an/a16.04

External Links