Описание
wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.
Ссылки
- Vendor Advisory
- ExploitPatch
- PatchVendor Advisory
- Vendor Advisory
- ExploitPatch
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.6 (включая)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
EPSS
Процентиль: 84%
0.0263
Низкий
3.5 Low
CVSS2
Дефекты
CWE-264
Связанные уязвимости
ubuntu
почти 13 лет назад
wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.
debian
почти 13 лет назад
wp-admin/includes/post.php in WordPress before 3.6.1 allows remote aut ...
github
около 4 лет назад
wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.
EPSS
Процентиль: 84%
0.0263
Низкий
3.5 Low
CVSS2
Дефекты
CWE-264