WordPress Core < 2.0.4 - Privilege Escalation

2006-07-09 00:00
Anonymous

Strategic Overview

Status
Patched in 2.0.4
Affected CoreWordPress 2.0
Affected Version< 2.0.4
CVSS9.8Critical
CVECVE-2006-4028
View all WordPress 2.0 vulnerabilities

Vulnerability Overview

Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due to lack of details, it is not clear how these issues are different from CVE-2006-3389 and CVE-2006-3390, although it is likely that 2.0.4 addresses an unspecified issue related to "Anyone can register" functionality (user registration for guests).

Technical Analysis

REMEDIATION: Update to version 2.0.4, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C