Skip to content

WordPress: 'set-screen-option' filter misuse by plugins leading to privilege escalation

Moderate
ehti published GHSA-4vpv-fgg2-gcqc Jun 12, 2020

Package

No package listed

Affected versions

3.7 - 5.4.1

Patched versions

5.4.2

Description

Impact

Misuse of the set-screen-option filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged by low privileged users.

Patches

This has been patched in WordPress 5.4.2, along with all the previously affected versions via a minor release. Automatic updates are enabled by default for minor releases and we strongly recommend that you keep them enabled.

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2020-4050

Weaknesses

No CWEs