Total vulnerabilities in the database
is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).
Software | From | Fixed in |
---|---|---|
WordPress / wordpress | - | 5.5.2 |
fedoraproject / fedora | 31 | 31.x |
fedoraproject / fedora | 32 | 32.x |
fedoraproject / fedora | 33 | 33.x |
debian / debian_linux | 10.0 | 10.0.x |