
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-28040 is a security vulnerability discovered in WordPress versions before 5.5.2 that allows Cross-Site Request Forgery (CSRF) attacks specifically targeting the theme's background image functionality. The vulnerability was disclosed and patched in October 2020 as part of WordPress 5.5.2 security release (WordPress News).
The vulnerability is classified as a Cross-Site Request Forgery (CSRF) issue with a CVSS v3.1 Base Score of 4.3 (MEDIUM) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N. The vulnerability requires user interaction and can result in low impact to integrity while not affecting confidentiality or availability (NVD).
If exploited, this vulnerability allows attackers to perform unauthorized changes to a WordPress site's theme background image through CSRF attacks. The attack requires user interaction and can only affect the visual appearance of the website through manipulation of theme settings (NVD).
The vulnerability requires network access and user interaction to be exploited. It has a medium complexity attack vector, requiring no authentication but necessitating user interaction for successful exploitation (NVD).
The vulnerability was fixed in WordPress version 5.5.2. Users are strongly recommended to upgrade to this version or later. The fix was also backported to all WordPress versions since 3.7 through security releases. Various Linux distributions including Debian and Fedora have released security updates to address this vulnerability (Debian Security, Fedora Update).
The vulnerability was responsibly disclosed by Erwan LR from WPScan, and the WordPress security team promptly addressed it in the 5.5.2 security release. The discovery and fix were acknowledged in the WordPress 5.5.2 release notes, demonstrating the effectiveness of the WordPress security response process (WordPress News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."