WordPress Core < 4.7.2 - Path Disclosure
2017-01-01 00:00
AnonymousStrategic Overview
StatusPatched in 3.7.18
Affected CoreWordPress 4.7
Affected Version
3.7 – 4.7.1 · 12 branchesCVSS4.3Medium
CVE
CVE-2017-6514Vulnerability Overview
WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.
Technical Analysis
REMEDIATION: Update to one of the following versions, or a newer patched version: 3.7.18, 3.8.18, 3.9.16, 4.0.15, 4.1.15, 4.2.12, 4.3.8, 4.4.7, 4.5.6, 4.6.3, 4.7.2 --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C