WordPress Core < 5.2.4 - Authorization Bypass
2019-10-14 00:00
J.D. GrimesStrategic Overview
StatusPatched in 3.7.31
Affected CoreWordPress 5.2
Affected Version
3.7 – 5.2.3 · 17 branchesCVSS5.3Medium
CVE
CVE-2019-17671Vulnerability Overview
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is mishandled.
Technical Analysis
REMEDIATION: Update to one of the following versions, or a newer patched version: 3.7.31, 3.8.31, 3.9.29, 4.0.28, 4.1.28, 4.2.25, 4.3.21, 4.4.20, 4.5.19, 4.6.16, 4.7.15, 4.8.11, 4.9.12, 5.0.7, 5.1.3, 5.2.4 --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C