Israeli security researcher Barak Tawily has released a vulnerability tracked as CVE-2018-6389 that could be exploited to trigger DoS condition of WordPress websites. The vulnerability exists in almost all versions of WordPress released in last nine years, including the latest one (Version 4.9.2) The flaw affects the load-scripts.php WordPress script, it receives a. parameter called load[] with value is jquery-ui-core In the response, the CMS. provides the. JS module ‘jQuery UI Core that was requested. The. response provided by the WordPress CMS depends upon the installed plugins and modules.”]
Source: https://securityaffairs.co/wordpress/68709/hacking/cve-2018-6389-wordpress-dos-flaw.html

