{"id":"CVE-2018-6389","details":"In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.","modified":"2026-07-08T18:16:09.287279Z","published":"2018-02-06T17:29:00.253Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/103060"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1040347"},{"type":"ADVISORY","url":"https://github.com/WazeHell/CVE-2018-6389"},{"type":"ADVISORY","url":"https://wpvulndb.com/vulnerabilities/9021"},{"type":"REPORT","url":"https://baraktawily.blogspot.fr/2018/02/how-to-dos-29-of-world-wide-websites.html"},{"type":"EVIDENCE","url":"https://github.com/UltimateHackers/Shiva"},{"type":"EVIDENCE","url":"https://thehackernews.com/2018/02/wordpress-dos-exploit.html"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/43968/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wordpress/wordpress","events":[{"introduced":"0"},{"last_affected":"cfa1b0b98456220b4942a953a6792cd9cf00abc2"}],"database_specific":{"cpe":"cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"4.9.2"}],"source":"CPE_RANGE"}}],"versions":["4.9.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-6389.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/wordpress/wordpress-develop","events":[{"introduced":"0"},{"last_affected":"425f42429c08bdf8f1cdcc01bdcecb8468f7226c"}],"database_specific":{"cpe":"cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"4.9.2"}],"source":"CPE_RANGE"}}],"versions":["4.9.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-6389.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}