
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-28035 is a security vulnerability discovered in WordPress versions before 5.5.2 that allows attackers to gain privileges via XML-RPC. The vulnerability was disclosed and patched in October 2020 as part of WordPress 5.5.2 security release (WordPress Release).
The vulnerability has been assigned a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a critical severity level with network attack vector, low attack complexity, and no required privileges or user interaction (NVD).
The vulnerability allows attackers to escalate privileges through WordPress's XML-RPC functionality, potentially gaining unauthorized access to higher privilege levels within the WordPress installation (WPScan).
The vulnerability affects WordPress installations prior to version 5.5.2 and can be exploited remotely through XML-RPC functionality. The low attack complexity and lack of required privileges make this vulnerability highly exploitable (NVD).
The vulnerability was fixed in WordPress version 5.5.2. Users are strongly recommended to upgrade to this version or later. Multiple Linux distributions have also released security updates to address this vulnerability, including Debian and Fedora (Debian Advisory, Fedora Advisory).
The vulnerability was responsibly disclosed by security researcher Justin Tran, who also identified related XML-RPC privilege escalation issues. The WordPress security team acknowledged his contribution in the 5.5.2 release notes (WordPress Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."