WordPress Core < 3.0.1 - Missing Authorization

2010-07-29 00:00
Anonymous

Strategic Overview

Status
Patched in 3.0.1
Affected CoreWordPress 3.0
Affected Version< 3.0.1
CVSS4.7Medium
CVECVE-2010-5297
View all WordPress 3.0 vulnerabilities

Vulnerability Overview

WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.

Technical Analysis

REMEDIATION: Update to version 3.0.1, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C