Описание
wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.
Ссылки
- Vendor Advisory
- ExploitPatch
- PatchVendor Advisory
- Vendor Advisory
- ExploitPatch
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.6 (включая)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
EPSS
Процентиль: 76%
0.00977
Низкий
3.5 Low
CVSS2
Дефекты
CWE-264
Связанные уязвимости
ubuntu
около 12 лет назад
wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.
debian
около 12 лет назад
wp-admin/includes/post.php in WordPress before 3.6.1 allows remote aut ...
github
больше 3 лет назад
wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.
EPSS
Процентиль: 76%
0.00977
Низкий
3.5 Low
CVSS2
Дефекты
CWE-264