WordPress 5.7.2 release contains a fix for a critical vulnerability

Person working on a WordPress post
(Image credit: Pixabay)

WordPress users are being urged to update to version 5.7.2 as soon as possible as the latest release of the world's most popular CMS includes a security patch that addresses a critical vulnerability.

The vulnerability, tracked as CVE-2020-36326, affects WordPress versions 3.7 to 5.7 and has been given a critical severity rating of 9.8 as it could allow an attacker to perform a variety of malicious attacks against an unpatched site.

While the update containing the patch is now available to download manually, WordPress sites that have automatic downloads enabled will receive it without the need for any additional action. 

Site owners should will still need to check and see if they are running the latest version and if not, they should install it themselves to prevent falling victim to any potential attacks exploiting this vulnerability.

Object Injection flaw

The flaw itself is an Object Injection vulnerability found in WordPress' PHPMailer component that is used to send emails by default.

According to the security firm Wordfence, all Object Injection vulnerabilities require a “POP Chain” in order to cause additional damage. This means that additional software with a vulnerable magic method would need to be running on a WordPress site to exploit this vulnerability, making it quite difficult to do.

In a new blog post, Wordfence's Ram Gall explained how an attacker could potentially exploit this vulnerability, saying:

“Although anyone with direct access to PHPMailer might be able to inject a PHP object, warranting a critical severity rating in the PHPMailer component itself, WordPress does not allow users this type of direct access. Instead, all access occurs through functionality exposed in core and in various plugins. In order to exploit this, an attacker would need to find a way to send a message using PHPMailer and add an attachment to that message. Additionally, the attacker would need to find a way to completely control the path to the attachment.” 

Although it would be quite difficult for an attacker to exploit this vulnerability in the wild, site owners are being encouraged to still update their WordPress core to the latest version if they have not done so already.

Via Search Engine Journal

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Another serious WordPress plugin vulnerability could put 40,000 sites at risk of attack
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Top WordPress plugins found to have some serious security flaws, so make sure you're protected
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Over a million WordPress sites exposed to attack from W3 Total Cache plugin flaw
WordPress
Another top WordPress plugin found carrying critical security flaws
WordPress
Security flaw in top WordPress plugin could allow for Stripe refunds on millions of sites
WordPress
WordPress users beware - these popular theme plugins have some major security issues
Latest in Website Building
Squarespace
Don't miss out on this great Squarespace deal
Hostinger Website Builder vs WordPress.com: Which is better?
Hostinger Website Builder vs WordPress.com: Battle of the WordPress website builders
Wix Business Launcher vs GoDaddy Airo: What's better for businesses?
Weebly vs Wix: Which offers a better free plan?
Wix Business Launcher vs GoDaddy Airo: What's better for businesses?
Wix Business Launcher vs GoDaddy Airo: Which is better for small businesses?
Wix AI vs Squarespace Blueprint: Who has the better AI?
Wix AI vs Squarespace Blueprint: Which website builder has better AI?
Hostinger logo
Grab an impressive 15% off your Hostinger website builder plan for a limited time
Latest in News
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection
iPad Air M3
Apple makes one hardware change to the iPad Air that might be the best indicator of its true lightweight tablet intentions
Shure MoveMic 88+ lifestyle image
Shure's tiny MoveMic 88+ gives creators a cheap and easy way to record crystal clear audio on a smartphone
An operator fires a saw blade from a weapon
Call of Duty: Black Ops 6 Season 3 gets two-week delay, will now release in April
Apple iPad A16
Apple's new entry-level iPad ups the performance for the same price, but doesn't support Apple Intelligence