Description
is_blog_installed in wp-includes/functions.php in WordPress before 5.5.2 improperly determines whether WordPress is already installed, which might allow an attacker to perform a new installation, leading to remote code execution (as well as a denial of service for the old installation).
Remediation
References
Related Vulnerabilities
PHP Other Vulnerability (CVE-2015-6834)
WordPress Plugin Maps Widget for Google Maps-Google Maps Builder Security Bypass (4.16)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-4301)
WordPress Plugin Simple Sitemap-Create a Responsive HTML Sitemap Cross-Site Scripting (3.5.7)
Jboss EAP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-9518)