Debian Security Advisory

DLA-860-1 wordpress -- LTS security update

Date Reported:
17 Mar 2017
Affected Packages:
wordpress
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 857026.
In Mitre's CVE dictionary: CVE-2017-6814, CVE-2017-6815, CVE-2017-6816.
More information:

Several vulnerabilities were discovered in wordpress, a web blogging tool. The Common Vulnerabilities and Exposures project identifies the following issues.

  • CVE-2017-6814

    Cross-Site Scripting (XSS) vulnerability via media file metadata

  • CVE-2017-6815

    Control characters can trick redirect URL validation in wp-includes/pluggable.php

  • CVE-2017-6816

    Unintended files can be deleted by administrators using the plugin deletion functionality

For Debian 7 Wheezy, these problems have been fixed in version 3.6.1+dfsg-1~deb7u14.

We recommend that you upgrade your wordpress packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS