WordPress Unsupported Version Detection

critical Nessus Plugin ID 84019

Synopsis

The remote host is running an unsupported version of WordPress.

Description

According to its self-reported version number, the installation of WordPress running on the remote host is no longer supported.

Lack of support implies that no new security patches for the product will be released by the vendor. As a result, it is likely to contain security vulnerabilities.

Note that any new patches for previous versions are unofficial and are not guaranteed to be continued in the future.

Solution

Upgrade to a version of WordPress that is currently supported.

See Also

https://codex.wordpress.org/WordPress_Versions

http://www.nessus.org/u?0022ddd0

Plugin Details

Severity: Critical

ID: 84019

File Name: wordpress_unsupported.nasl

Version: 1.17

Type: remote

Family: CGI abuses

Published: 6/8/2015

Updated: 6/5/2024

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Enable CGI Scanning: true

Risk Information

CVSS Score Rationale: Tenable score for unsupported software.

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: manual

CVSS v3

Risk Factor: Critical

Base Score: 10

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:wordpress:wordpress

Required KB Items: installed_sw/WordPress, Settings/ParanoidReport

Excluded KB Items: Settings/disable_cgi_scanning

Reference Information

IAVA: 0001-A-0625