CVE-2018-6389
WordPress Core < 5.0 - Denial of Service
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
15Exploited in Wild
-Decision
Descriptions
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.
En WordPress hasta la versiĆ³n 4.9.2, los atacantes no autenticados puede provocar una denegaciĆ³n de servicio (consumo de recursos) utilizando una lista grande de archivos .js registrados (de wp-includes/script-loader.php) para construir una serie de peticiones para cargar cada archivo muchas veces.
In WordPress before 5.0, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times. It looks like most of the slowness was due to forcing PHP to repeatedly compress the output scripts, which was addressed in 5.0.
WordPress Core suffers from a load-scripts.php denial of service vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-01-29 CVE Reserved
- 2018-02-05 CVE Published
- 2018-02-06 First Exploit
- 2024-08-05 CVE Updated
- 2024-09-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (19)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/103060 | Third Party Advisory | |
http://www.securitytracker.com/id/1040347 | Third Party Advisory | |
https://github.com/WazeHell/CVE-2018-6389 | Third Party Advisory | |
https://wpvulndb.com/vulnerabilities/9021 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | <= 4.9.2 Search vendor "Wordpress" for product "Wordpress" and version " <= 4.9.2" | - |
Affected
|