Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fp5j-7rg9-v2c7

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

EPSS

Процентиль: 98%
0.52947
Средний

Дефекты

CWE-284

Связанные уязвимости

ubuntu
около 10 лет назад

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

nvd
около 10 лет назад

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

debian
около 10 лет назад

WordPress before 4.2.3 does not properly verify the edit_posts capabil ...

EPSS

Процентиль: 98%
0.52947
Средний

Дефекты

CWE-284