CVE-2023-2745

WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the wp_lang parameter. This allows unauthenticated attackers to access and load arbitrary translation files. In cases where an attacker is able to upload a crafted translation file onto the site, such as via an upload form, this could be also used to perform a Cross-Site Scripting attack.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
WordfenceCNA
5.4 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
wordpresswordpress
𝑥
< 4.1.38
wordpresswordpress
4.2 ≤
𝑥
< 4.2.35
wordpresswordpress
4.3 ≤
𝑥
< 4.3.31
wordpresswordpress
4.4 ≤
𝑥
< 4.4.30
wordpresswordpress
4.5 ≤
𝑥
< 4.5.29
wordpresswordpress
4.6 ≤
𝑥
< 4.6.26
wordpresswordpress
4.7 ≤
𝑥
< 4.7.26
wordpresswordpress
4.8 ≤
𝑥
< 4.8.22
wordpresswordpress
4.9 ≤
𝑥
< 4.9.23
wordpresswordpress
5.0 ≤
𝑥
< 5.0.19
wordpresswordpress
5.1 ≤
𝑥
< 5.1.16
wordpresswordpress
5.2 ≤
𝑥
< 5.2.18
wordpresswordpress
5.3 ≤
𝑥
< 5.3.15
wordpresswordpress
5.4 ≤
𝑥
< 5.4.13
wordpresswordpress
5.5 ≤
𝑥
< 5.5.12
wordpresswordpress
5.6 ≤
𝑥
< 5.6.11
wordpresswordpress
5.7 ≤
𝑥
< 5.7.9
wordpresswordpress
5.8 ≤
𝑥
< 5.8.7
wordpresswordpress
5.9 ≤
𝑥
< 5.9.6
wordpresswordpress
6.0 ≤
𝑥
< 6.0.4
wordpresswordpress
6.1 ≤
𝑥
< 6.1.2
wordpresswordpress
6.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
wordpress
bullseye (security)
5.7.11+dfsg1-0+deb11u1
fixed
bullseye
5.7.11+dfsg1-0+deb11u1
fixed
bookworm
6.1.6+dfsg1-0+deb12u1
fixed
bookworm (security)
6.1.6+dfsg1-0+deb12u1
fixed
sid
6.6.1+dfsg1-1
fixed
trixie
6.6.1+dfsg1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
wordpress
oracular
not-affected
noble
needs-triage
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
needs-triage
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
ignored