WordPress Core < 3.5.2 - Missing Authorization Checks

2013-06-21 00:00
Konstantin Kovshenin

Strategic Overview

Status
Patched in 3.5.2
Affected CoreWordPress 3.5
Affected Version<= 3.5.1
CVSS6.3Medium
CVECVE-2013-2200
View all WordPress 3.5 vulnerabilities

Vulnerability Overview

WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended restrictions on publishing and authorship reassignment via unspecified vectors.

Technical Analysis

REMEDIATION: Update to version 3.5.2, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C