{"document":{"aggregate_severity":{"text":"hoch"},"category":"csaf_base","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"de-DE","notes":[{"category":"legal_disclaimer","text":"Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen."},{"category":"description","text":"WordPress ist ein PHP basiertes Open Source Blog-System.","title":"Produktbeschreibung"},{"category":"summary","text":"Ein Angreifer kann mehrere Schwachstellen in WordPress ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe durchzuführen oder Daten zu manipulieren und offenzulegen.","title":"Angriff"},{"category":"general","text":"- Linux\n- Sonstiges\n- UNIX\n- Windows","title":"Betroffene Betriebssysteme"}],"publisher":{"category":"other","contact_details":"csaf-provider@cert-bund.de","name":"Bundesamt für Sicherheit in der Informationstechnik","namespace":"https://www.bsi.bund.de"},"references":[{"category":"self","summary":"WID-SEC-W-2026-3472 - CSAF Version","url":"https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3472.json"},{"category":"self","summary":"WID-SEC-2026-3472 - Portal Version","url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3472"},{"category":"external","summary":"WordPress 7.1.1 Maintenance and Security Release vom 2026-09-20","url":"https://wordpress.org/news/2026/09/wordpress-7-1-1-maintenance-and-security-release/"},{"category":"external","summary":"GitHub Security Advisory GHSA-32m5-wc28-ghrr vom 2026-09-20","url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-32m5-wc28-ghrr"},{"category":"external","summary":"GitHub Security Advisory GHSA-33wf-p63q-w25f vom 2026-09-20","url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-33wf-p63q-w25f"},{"category":"external","summary":"GitHub Security Advisory GHSA-5qf7-2r5p-ppj8 vom 2026-09-20","url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-5qf7-2r5p-ppj8"},{"category":"external","summary":"Pwn.ai Research - Click2Shell vom 2026-09-20","url":"https://pwn.ai/blog/click2shell"},{"category":"external","summary":"GitHub Security Advisory GHSA-76jg-r2qr-v77f vom 2026-09-20","url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-76jg-r2qr-v77f"},{"category":"external","summary":"GitHub Security Advisory GHSA-cjfg-q57r-mq45 vom 2026-09-20","url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-cjfg-q57r-mq45"},{"category":"external","summary":"GitHub Security Advisory GHSA-f522-h982-63mg vom 2026-09-20","url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-f522-h982-63mg"},{"category":"external","summary":"GitHub Security Advisory GHSA-mgvw-845h-9qgq vom 2026-09-20","url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-mgvw-845h-9qgq"},{"category":"external","summary":"GitHub Security Advisory GHSA-qg7r-fjh2-wvx8 vom 2026-09-20","url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-qg7r-fjh2-wvx8"},{"category":"external","summary":"GitHub Security Advisory GHSA-rmpv-w5v9-rqh5 vom 2026-09-20","url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-rmpv-w5v9-rqh5"},{"category":"external","summary":"GitHub Security Advisory GHSA-w57f-v787-qhpf vom 2026-09-20","url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-w57f-v787-qhpf"},{"category":"external","summary":"GitHub Security Advisory GHSA-xhp5-863h-rhfr vom 2026-09-20","url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-xhp5-863h-rhfr"},{"category":"external","summary":"Comment2Shell: Zero-Click Pre-Auth XSS to RCE in WordPress Core vom 2026-09-21","url":"https://idnsec.com/research/comment2shell-zero-click-pre-auth-xss-to-rce-in-wordpress-core/"}],"source_lang":"en-US","title":"WordPress: Mehrere Schwachstellen","tracking":{"current_release_date":"2026-09-21T22:00:00.000+00:00","generator":{"date":"2026-09-22T07:31:32.695+00:00","engine":{"name":"BSI-WID","version":"1.6.0"}},"id":"WID-SEC-W-2026-3472","initial_release_date":"2026-09-20T22:00:00.000+00:00","revision_history":[{"date":"2026-09-20T22:00:00.000+00:00","number":"1","summary":"Initiale Fassung"},{"date":"2026-09-21T22:00:00.000+00:00","number":"2","summary":"CVE + Bezeichner \"Comment2Shell\" ergänzt"}],"status":"final","version":"2"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_version_range","name":"<7.1.1","product":{"name":"Open Source WordPress <7.1.1","product_id":"T059881"}},{"category":"product_version","name":"7.1.1","product":{"name":"Open Source WordPress 7.1.1","product_id":"T059881-fixed","product_identification_helper":{"cpe":"cpe:/a:wordpress:wordpress:7.1.1"}}}],"category":"product_name","name":"WordPress"}],"category":"vendor","name":"Open Source"}]},"vulnerabilities":[{"cve":"CVE-2026-93485","product_status":{"known_affected":["T059881"]},"release_date":"2026-09-20T22:00:00.000+00:00","title":"CVE-2026-93485"}]}