peter bassill · operator
$ cve CVE-2008-5695 JSON

CVE-2008-5695 EXPLOIT

8.5
HIGH · CVSS 2.0 · EPSS 12% (pctl 96)

Patch early

A public exploit exists.

Description

wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script's pathname to active_plugins.

Scoring

CVSS8.5 (HIGH, v2.0)
VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
EPSS12.01% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2008-12-19
Last modified2026-06-16

Affected (2)

VendorProduct
wordpresswordpress
wordpresswordpress mu

Public exploits

SourceTitleDate
exploit-dbWordPress MU < 1.3.2 - 'active_plugins' Code Execution2008-02-05

References

→ the Explorer  ·  watch your stack  ·  NVD