CVE-2020-28035
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-28035 is a security vulnerability discovered in WordPress versions before 5.5.2 that allows attackers to gain privileges via XML-RPC. The vulnerability was disclosed and patched in October 2020 as part of WordPress 5.5.2 security release (WordPress Release).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a critical severity level with network attack vector, low attack complexity, and no required privileges or user interaction (NVD).

Impact

The vulnerability allows attackers to escalate privileges through WordPress's XML-RPC functionality, potentially gaining unauthorized access to higher privilege levels within the WordPress installation (WPScan).

Exploitability

The vulnerability affects WordPress installations prior to version 5.5.2 and can be exploited remotely through XML-RPC functionality. The low attack complexity and lack of required privileges make this vulnerability highly exploitable (NVD).

Mitigation and workarounds

The vulnerability was fixed in WordPress version 5.5.2. Users are strongly recommended to upgrade to this version or later. Multiple Linux distributions have also released security updates to address this vulnerability, including Debian and Fedora (Debian Advisory, Fedora Advisory).

Community reactions

The vulnerability was responsibly disclosed by security researcher Justin Tran, who also identified related XML-RPC privilege escalation issues. The WordPress security team acknowledged his contribution in the 5.5.2 release notes (WordPress Release).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management