CVE-2019-17671
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 37%
from disclosure to weapon0 days
Published on NVDOct 17
1st PoCOct 14
exploitation probability
37%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/47690unverifiedgithubgithub.com/rhbb/CVE-2019-17671★ 2⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://blog.wpscan.org/wordpress/security/release/2019/10/15/wordpress-524-security-release-breakdown.htmlhttps://core.trac.wordpress.org/changeset/46474https://github.com/WordPress/WordPress/commit/f82ed753cf00329a5e41f2cb6dc521085136f308https://lists.debian.org/debian-lts-announce/2019/11/msg00000.htmlhttps://seclists.org/bugtraq/2020/Jan/8https://wordpress.org/news/2019/10/wordpress-5-2-4-security-release/https://wpvulndb.com/vulnerabilities/9909https://www.debian.org/security/2020/dsa-4599https://www.debian.org/security/2020/dsa-4677