CVE-2020-28033
NixOS vulnerability analysis and mitigation

Overview

WordPress versions before 5.5.2 contain a security vulnerability identified as CVE-2020-28033. The vulnerability was discovered in October 2020 and involves the mishandling of embeds from disabled sites on a multisite network, which could potentially allow spam embeds (WordPress News, Debian Security).

Technical details

The vulnerability is related to how WordPress handles embeds from disabled sites within a multisite network configuration. It has a CVSS 3.1 base score of 7.5 (High), with the following characteristics: Network attack vector, Low attack complexity, No privileges required, No user interaction needed, Unchanged scope, No impact on confidentiality, High impact on integrity, and No impact on availability (Ubuntu Security).

Impact

The primary impact of this vulnerability is that it allows attackers to embed spam content from disabled sites on a multisite network. This could potentially lead to unauthorized content being displayed on affected WordPress installations (WordPress News).

Exploitability

The vulnerability requires no special privileges or user interaction to exploit, making it relatively straightforward to take advantage of. The attack can be executed remotely over the network, though specific details about exploits in the wild are not publicly documented (Ubuntu Security).

Mitigation and workarounds

The vulnerability was patched in WordPress version 5.5.2. Users are strongly recommended to upgrade to this version or later. The fix was also backported to all WordPress versions since 3.7 through security releases. Various Linux distributions have also released security updates, including Debian (5.0.11+dfsg1-0+deb10u1) and Fedora (5.5.3-1) (Debian Security, WordPress News).

Community reactions

The security fix was credited to David Binovec, who discovered and helped resolve the vulnerability. The WordPress security team coordinated the release of patches across multiple versions, demonstrating their commitment to maintaining security across their entire user base (WordPress News).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13097CRITICAL9.1
  • NixOS logoNixOS
  • python3-samba-test
NoYesAug 20, 2026
CVE-2026-11861HIGH8.1
  • NixOS logoNixOS
  • samba-common
NoYesAug 20, 2026
CVE-2026-73198HIGH7.5
  • NixOS logoNixOS
  • ctdb-ceph-mutex
NoYesAug 20, 2026
CVE-2026-73197HIGH7.5
  • NixOS logoNixOS
  • samba-test-libs-debuginfo
NoYesAug 20, 2026
CVE-2026-73196MEDIUM6.5
  • NixOS logoNixOS
  • samba-ldb-ldap-modules-debuginfo
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management