Description
WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service calls with a source URI that corresponds to a local pathname, which triggers different fault codes for existing and non-existing files, and in certain configurations causes a brief file excerpt to be published as a blog comment.
Remediation
References
Related Vulnerabilities
WordPress 3.9.x Cross-Site Request Forgery (3.9 - 3.9.26)
WordPress Plugin OneLogin SAML SSO Security Bypass (2.2.0)
WebLogic CVE-2021-1996 Vulnerability (CVE-2021-1996)
Apache Tomcat 7PK - Security Features Vulnerability (CVE-2014-9635)
WordPress Plugin Podlove Podcast Publisher Multiple Cross-Site Scripting Vulnerabilities (2.1.0)