WordPress Core < 3.0.3 - Access Control Bypass

2010-12-08 00:00
Anonymous

Strategic Overview

Status
Patched in 3.0.3
Affected CoreWordPress 3.0
Affected Version<= 3.0.2
CVSS6.3Medium
CVECVE-2010-5106
View all WordPress 3.0 vulnerabilities

Vulnerability Overview

The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.

Technical Analysis

REMEDIATION: Update to version 3.0.3, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C