This is a notice from the Information Security Office to alert you to a critical vulnerability that impacts WordPress, a common website management platform[1]. Please share this alert internally with IT admins and service owners who run the product so they are aware and know what actions to take to address this vulnerability.
SUMMARY
ISO is aware of two vulnerabilities, with Critical and High Severity, that affect WordPress 6.8, 6.9, 7.0, and 7.1 (beta). These vulnerabilities take advantage of SQL Injection issues in the user interface and REST API, allowing Remote Code Execution in the case of the API vulnerability.
IMPACT
If exploited, remote users (potentially unauthenticated users) could run commands against the site, including modifying content and uploading and executing malicious code.
WHAT IS VULNERABLE
Vulnerable versions include:
- WordPress 7.0 before 7.0.2
- WordPress 6.9 before 6.9.5
- WordPress 6.8 before 6.8.6
- WordPress 7.1 beta
WordPress versions earlier than 6.8 are NOT impacted.
RECOMMENDATIONS
-
Upgrade to a patched version of WordPress as soon as possible:
-
WordPress 7.0.2
-
WordPress 6.9.5
-
WordPress 6.8.6
-
WordPress 7.1 beta2
REFERENCES
If you have any questions about the vulnerability or would like some assistance patching or mitigating it, please contact security@berkeley.edu.