← back
CVE-2019-8942observed exploitation

CVE-2019-8942

84Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 83%
from disclosure to weapon5 days
Published on NVDFeb 20
1st PoC+5d
metasploitFeb 19
VulnCheck+782d
exploitation probability
83%top 1% of all CVEs
observed exploitation
yesVulnCheck
13 public exploit(s)
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.