WordPress Core < 4.3.1 - Authorization Bypass to Information Disclosure
2015-09-15 00:00
Shahar TalStrategic Overview
StatusPatched in 3.7.11
Affected CoreWordPress 4.3
Affected Version
3.7 – 4.3 · 8 branchesCVSS5.4Medium
CVE
CVE-2015-5715Vulnerability Overview
The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via unspecified vectors.
Technical Analysis
REMEDIATION: Update to one of the following versions, or a newer patched version: 3.7.11, 3.8.11, 3.9.9, 4.0.8, 4.1.8, 4.2.5, 4.3.1 --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C