Your submission was sent successfully! Close

CVE-2022-21663

Published: 6 January 2022

WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in WordPress version 5.8.3. Older affected versions are also fixed via security release, that go back till 3.7.37. We strongly recommend that you keep auto-updates enabled. There are no known workarounds for this issue.

Priority

Low

CVSS 3 base score: 7.2

Status

Package Release Status
wordpress
Launchpad, Ubuntu, Debian
bionic Needs triage

focal Needs triage

hirsute Ignored
(reached end-of-life)
impish Needs triage

jammy Not vulnerable
(5.8.3+dfsg1-1ubuntu1)
trusty Ignored
(out of standard support)
upstream
Released (5.8.3+dfsg1-1)
xenial Ignored
(out of standard support)