Improper Installation Check in WordPress Allows Unauthorized Access
CVE-2020-28037

9.8CRITICAL

Key Information:

Vendor

Wordpress

Status
Vendor
CVE Published:
2 November 2020

What is CVE-2020-28037?

An issue has been identified in WordPress where the function responsible for determining whether WordPress is already installed fails to perform its task correctly. This vulnerability could allow an unauthorized user to initiate a new installation of WordPress. The impact of this flaw could lead to the potential execution of remote code, which can compromise the existing site and initiate denial of service conditions for the original installation. Users are advised to update to WordPress version 5.5.2 or higher to mitigate risks linked to this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

EPSS Score

12% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.