logoalt Hacker News

pauleztoday at 5:13 PM2 repliesview on HN

This score specifically means that given some specific conditions, anyone can execute code over the network on a vulnerable WordPress setup. Is this not true?


Replies

tptacektoday at 5:19 PM

I'm not saying that the vulnerability isn't severe or important to people running Wordpress, only that CVSS scores are literally a Ouija Board that can come out to whatever the user wants them to.

show 2 replies
bombcartoday at 5:40 PM

My assumption is that any Wordpress setup whatsoever allows anyone to execute code remotely.

show 1 reply