Логотип exploitDog
bind:CVE-2015-5623
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-5623

Количество 4

Количество 4

ubuntu логотип

CVE-2015-5623

около 10 лет назад

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

CVSS2: 4
EPSS: Средний
nvd логотип

CVE-2015-5623

около 10 лет назад

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

CVSS2: 4
EPSS: Средний
debian логотип

CVE-2015-5623

около 10 лет назад

WordPress before 4.2.3 does not properly verify the edit_posts capabil ...

CVSS2: 4
EPSS: Средний
github логотип

GHSA-fp5j-7rg9-v2c7

около 3 лет назад

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2015-5623

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

CVSS2: 4
43%
Средний
около 10 лет назад
nvd логотип
CVE-2015-5623

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

CVSS2: 4
43%
Средний
около 10 лет назад
debian логотип
CVE-2015-5623

WordPress before 4.2.3 does not properly verify the edit_posts capabil ...

CVSS2: 4
43%
Средний
около 10 лет назад
github логотип
GHSA-fp5j-7rg9-v2c7

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

43%
Средний
около 3 лет назад

Уязвимостей на страницу