|Description||wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script's pathname to active_plugins.|
|Source||CVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)|
|Debian Bugs||510786, 513959|
Vulnerable and fixed packages
The table below lists information on source packages.
|wordpress (PTS)||stretch (security), stretch||4.7.5+dfsg-2+deb9u6||fixed|
|buster, buster (security)||5.0.10+dfsg1-0+deb10u1||fixed|
The information below is based on the following data on fixed versions.
[etch] - wordpress <no-dsa> (Minor issue)
only the admin has manage_options capabilities by default and only editors
have upload_files capabilities
Only versions prior to 2.3.2 are affected according to the Debian maintainer