CVE-2017-1000600
Last modified
CVE-2017-1000600 is a vulnerability of currently unknown severity. WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time. EPSS estimates a 3.80% chance of exploitation in the next 30 days.
Description
WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time. This issue appears to have been partially, but not completely fixed in WordPress 4.9
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wordpress | Wordpress | < 4.9 |
References
- http://www.securityfocus.com/bid/105305Third Party Advisory, VDB Entry
- https://www.theregister.co.uk/2018/08/20/php_unserialisation_wordpress_vuln/Third Party Advisory
- https://youtu.be/GePBmsNJw6Y?t=1763Third Party Advisory
- http://www.securityfocus.com/bid/105305Third Party Advisory, VDB Entry
- https://www.theregister.co.uk/2018/08/20/php_unserialisation_wordpress_vuln/Third Party Advisory
- https://youtu.be/GePBmsNJw6Y?t=1763Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-1000600?
How severe is CVE-2017-1000600?
How do I fix CVE-2017-1000600?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-1000506Mautic version 2.11.0 and earlier contains a Cross Site Scri…
- CVE-2017-1000507Canvs Canvas version 3.4.2 contains a Cross Site Scripting (…
- CVE-2017-1000508Invoice Plane version 1.5.4 and earlier contains a Cross Sit…
- CVE-2017-1000509Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS)…
- CVE-2017-1000510Croogo version 2.3.1-17-g6f82e6c contains a Cross Site Scrip…
- CVE-2017-10006Vulnerability in the Oracle FLEXCUBE Private Banking compone…
- CVE-2017-10007Vulnerability in the Oracle FLEXCUBE Private Banking compone…
- CVE-2017-10008Vulnerability in the Oracle FLEXCUBE Private Banking compone…
- CVE-2017-10009Vulnerability in the Oracle FLEXCUBE Private Banking compone…
- CVE-2017-1001Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2017-10010Vulnerability in the Oracle FLEXCUBE Private Banking compone…
- CVE-2017-1001000The register_routes function in wp-includes/rest-api/endpoin…
Are you affected by CVE-2017-1000600?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
