---
title: "CVE-2021-39200"
canonical: "https://kb.cynergy.app/space/MD/923631950/CVE-2021-39200"
format: markdown
---
**Description**

Certain versions of [Debian Linux](https://cve.report/software/debian/debian_linux) from [Debian](https://cve.report/vendor/debian) contain the following vulnerability:

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like nonces. It can then be used to perform actions on your behalf. This has been patched in WordPress 5.8.1, along with any older affected versions via minor releases. It's strongly recommended that you keep auto-updates enabled to receive the fix.

**Published On**

09/09/2021

**Updated On**

12/14/2021

**Trending**

FALSE

**CWE**

[CWE-200](http://cwe.mitre.org/data/definitions/200.html)

**Exploit**

 

**Mitigation:**

![image](media://c3cedcdc-4cec-4370-9e1f-146a9478c650)

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span>

 

**Remediation**

- [154102](https://cve.report/qid/154102) WordPress Information Disclosure Vulnerability (CVE-2021-39200)
- [178825](https://cve.report/qid/178825) Debian Security Update for wordpress (DSA 4985-1)
- [180285](https://cve.report/qid/180285) Debian Security Update for wordpress (CVE-2021-39200)d to receive the fix.
  

**References**

|  |  |  |
| --- | --- | --- |
| HackerOne | [http://hackerone.com](http://hackerone.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| WordPress: Information Disclosure in wp_die() via JSONP, leading to CSRF · Advisory · WordPress/wordpress-develop · GitHub | [http://github.com](http://github.com)   
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |
| Debian -- Security Information -- DSA-4985-1 wordpress | [http://www.debian.org](http://www.debian.org)   
<span style="color: #ffffff">**Depreciated Link**</span>  
<span style="color: #ffffff">**text/html**</span> | ![URL Logo]() |