Описание
wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.
Ссылки
- Vendor Advisory
 - ExploitPatch
 - Vendor Advisory
 - ExploitPatch
 
Уязвимые конфигурации
Одно из
EPSS
4.9 Medium
CVSS2
Дефекты
Связанные уязвимости
wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.
wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisi ...
wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.
EPSS
4.9 Medium
CVSS2