Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v9p6-jxgm-w55j

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

EPSS

Процентиль: 48%
0.00242
Низкий

Связанные уязвимости

ubuntu
почти 13 лет назад

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

nvd
почти 13 лет назад

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

debian
почти 13 лет назад

The create_post function in wp-includes/class-wp-atom-server.php in Wo ...

EPSS

Процентиль: 48%
0.00242
Низкий