CVE-2018-20153
UnknownEPSS 2.47%
Last modified
CVE-2018-20153 is a vulnerability of currently unknown severity. In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.. EPSS estimates a 2.47% chance of exploitation in the next 30 days.
Description
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wordpress | Wordpress | < 4.9.9 |
| Wordpress | Wordpress | >= 5.0, < 5.0.1 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
References
- http://www.securityfocus.com/bid/106220Third Party Advisory, VDB Entry
- https://codex.wordpress.org/Version_4.9.9Product, Release Notes, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/02/msg00019.htmlThird Party Advisory
- https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/Release Notes, Vendor Advisory
- https://wordpress.org/support/wordpress-version/version-5-0-1/Release Notes, Vendor Advisory
- https://wpvulndb.com/vulnerabilities/9172Vendor Advisory
- https://www.debian.org/security/2019/dsa-4401Third Party Advisory
- https://www.zdnet.com/article/wordpress-plugs-bug-that-led-to-google-indexing-some-user-passwords/Press/Media Coverage, Third Party Advisory
- http://www.securityfocus.com/bid/106220Third Party Advisory, VDB Entry
- https://codex.wordpress.org/Version_4.9.9Product, Release Notes, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/02/msg00019.htmlThird Party Advisory
- https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/Release Notes, Vendor Advisory
- https://wordpress.org/support/wordpress-version/version-5-0-1/Release Notes, Vendor Advisory
- https://wpvulndb.com/vulnerabilities/9172Vendor Advisory
- https://www.debian.org/security/2019/dsa-4401Third Party Advisory
- https://www.zdnet.com/article/wordpress-plugs-bug-that-led-to-google-indexing-some-user-passwords/Press/Media Coverage, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-20153?
In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.
How severe is CVE-2018-20153?
Severity scoring for CVE-2018-20153 is pending analysis. The EPSS model estimates a 2.47% probability of exploitation in the next 30 days.
How do I fix CVE-2018-20153?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-20148In WordPress before 4.9.9 and 5.x before 5.0.1, contributors…
- CVE-2018-20149In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apa…
- CVE-2018-2015IBM API Connect 2018.1 and 2018.4.1.4 could allow a remote a…6.4
- CVE-2018-20150In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs…
- CVE-2018-20151In WordPress before 4.9.9 and 5.x before 5.0.1, the user-act…
- CVE-2018-20152In WordPress before 4.9.9 and 5.x before 5.0.1, authors coul…
- CVE-2018-20154The WP Maintenance Mode plugin before 2.0.7 for WordPress al…
- CVE-2018-20155The WP Maintenance Mode plugin before 2.0.7 for WordPress al…
- CVE-2018-20156The WP Maintenance Mode plugin before 2.0.7 for WordPress al…
- CVE-2018-20157The data import functionality in OpenRefine through 3.1 allo…
- CVE-2018-20159i-doit open 1.11.2 allows Remote Code Execution because ZIP …
- CVE-2018-20160ZxChat (aka ZeXtras Chat), as used for zimbra-chat and zimbr…
Are you affected by CVE-2018-20153?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
