CVE-2019-8942General(debian / debian_linux)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • wordpress

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
debian_linuxwordpress

2 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-08: 105-08
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • mr fancy hands@mr_fancy_hands
    General

    @batuhan @HSVSphere next.js is running tiktok, netflix and twitch, so not sure what your argument is supposed to be here. WordPress itself also had some horrible security issues (CVE-2017-1001000, CVE-2019-8942)

    Post summary

    The tweet simply references two WordPress CVEs without giving any technical, exploit, patch, or exploitation context.

    01080282
    257 followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux9.0--
Appwordpresswordpress---
Appwordpresswordpress5.0--
Appwordpresswordpress5.0--
Appwordpresswordpress5.0--
Appwordpresswordpress5.0--
Appwordpresswordpress5.0--
Appwordpresswordpress5.0--
Appwordpresswordpress5.0--
Appwordpresswordpress5.0--
Appwordpresswordpress5.0--

Explore more