Description
is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).
Remediation
References
Related Vulnerabilities
WordPress Plugin Passster Age Gate Security Bypass (4.0.6)
PostgreSQL Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2010-1169)
WordPress Plugin GNU-Mailman Integration Cross-Site Scripting (1.0.6)
Joomla! Core 4.x.x Multiple Vulnerabilities (4.0.0 - 4.2.6)
WordPress Plugin MoodThingy Mood Rating Widget 'postID' Parameter Blind SQL Injection (0.8.7)