In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.
References
Configurations
History
No history.
Information
Published : 2018-02-06 17:29
Updated : 2024-11-21 04:10
NVD link : CVE-2018-6389
Mitre link : CVE-2018-6389
CVE.ORG link : CVE-2018-6389
JSON object : View
Products Affected
wordpress
- wordpress
CWE
CWE-400
Uncontrolled Resource Consumption