Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-29450
HistoryApr 15, 2021 - 12:00 a.m.

CVE-2021-29450

2021-04-1500:00:00
ubuntu.com
ubuntu.com
21
wordpress
cms
vulnerability
password-protected
posts
php 8

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.007

Percentile

79.6%

Wordpress is an open source CMS. One of the blocks in the WordPress editor
can be exploited in a way that exposes password-protected posts and pages.
This requires at least contributor privileges. This has been patched in
WordPress 5.7.1, along with the older affected versions via minor releases.
It’s strongly recommended that you keep auto-updates enabled to receive the
fix.

Notes

Author Note
ebarretto only an issue when running with php 8.

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.007

Percentile

79.6%