CVE-2023-2745
WordPress Core < 6.2.1 - Directory Traversal
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.
Several security vulnerabilities have been discovered in Wordpress, a popular content management framework, which may lead to exposure of sensitive information to an unauthorized actor in WordPress or allowing unauthenticated attackers to discern the email addresses of users who have published public posts on an affected website via an Oracle style attack.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-05-16 CVE Reserved
- 2023-05-16 CVE Published
- 2023-05-17 First Exploit
- 2025-02-13 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (6)
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/172426 | 2023-05-17 |
URL | Date | SRC |
---|---|---|
https://core.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=55765%40%2F&new=55765%40%2F&sfp_email=&sfph_mail= | 2023-11-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | < 4.1.38 Search vendor "Wordpress" for product "Wordpress" and version " < 4.1.38" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 4.2 < 4.2.35 Search vendor "Wordpress" for product "Wordpress" and version " >= 4.2 < 4.2.35" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 4.3 < 4.3.31 Search vendor "Wordpress" for product "Wordpress" and version " >= 4.3 < 4.3.31" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 4.4 < 4.4.30 Search vendor "Wordpress" for product "Wordpress" and version " >= 4.4 < 4.4.30" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 4.5 < 4.5.29 Search vendor "Wordpress" for product "Wordpress" and version " >= 4.5 < 4.5.29" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 4.6 < 4.6.26 Search vendor "Wordpress" for product "Wordpress" and version " >= 4.6 < 4.6.26" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 4.7 < 4.7.26 Search vendor "Wordpress" for product "Wordpress" and version " >= 4.7 < 4.7.26" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 4.8 < 4.8.22 Search vendor "Wordpress" for product "Wordpress" and version " >= 4.8 < 4.8.22" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 4.9 < 4.9.23 Search vendor "Wordpress" for product "Wordpress" and version " >= 4.9 < 4.9.23" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.0 < 5.0.19 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.0 < 5.0.19" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.1 < 5.1.16 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.1 < 5.1.16" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.2 < 5.2.18 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.2 < 5.2.18" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.3 < 5.3.15 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.3 < 5.3.15" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.4 < 5.4.13 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.4 < 5.4.13" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.5 < 5.5.12 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.5 < 5.5.12" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.6 < 5.6.11 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.6 < 5.6.11" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.7 < 5.7.9 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.7 < 5.7.9" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.8 < 5.8.7 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.8 < 5.8.7" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 5.9 < 5.9.6 Search vendor "Wordpress" for product "Wordpress" and version " >= 5.9 < 5.9.6" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 6.0 < 6.0.4 Search vendor "Wordpress" for product "Wordpress" and version " >= 6.0 < 6.0.4" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | >= 6.1 < 6.1.2 Search vendor "Wordpress" for product "Wordpress" and version " >= 6.1 < 6.1.2" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 6.2 Search vendor "Wordpress" for product "Wordpress" and version "6.2" | - |
Affected
|