CVE-2019-8942: Debian Linux
High severity, CVSS 8.8. EPSS: 82.7% chance of exploitation in the next 30 days.
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry can be changed to an arbitrary string, such as one ending with a .jpg?file.php substring. An attacker with author privileges can execute arbitrary code by uploading a crafted image containing PHP code in the Exif metadata. Exploitation can leverage CVE-2019-8943.
Affected products
- Debian Debian Linux: version 9.0 only
- WordPress WordPress: before 4.9.9 (fixed in 4.9.9); version 5.0 only
Published 2019-02-20. Last modified 2026-06-17.