Secunia Advisory SA28823WordPress XML-RPC Post Edit Vulnerability
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
A vulnerability has been reported in WordPress, which can be exploited by malicious users to bypass certain security restrictions and to manipulate data. The xmlrpc.php script does not properly restrict access to the edit functionality. This can be exploited to edit other users' posts. Successful exploitation requires valid user credentials. The vulnerability is reported in version 2.3.2. Prior versions may also be affected. Solution Provided and/or discovered by Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
156 views | ![]() |
| Gentoo update for sarg | |
212 views | ![]() |
| Debian update for freetype | |