Lucene search

K
wpvulndbWpvulndbWPVDB-ID:2C423DC0-4FE4-4E5A-9386-412DE4FB2587
HistoryAug 01, 2014 - 12:00 a.m.

WordPress 2.9 - Failure to Restrict URL Access

2014-08-0100:00:00
wpscan.com
11

EPSS

0.006

Percentile

78.5%

When WordPress implemented the new Trash feature they failed to change the permissions granted when the post is in the trash. This means that an unauthenticated user cannot see the post, however an authenticated user can, no matter what privileges they have, even β€˜subscriber’. See ExploitDB for PoC

EPSS

0.006

Percentile

78.5%

Related for WPVDB-ID:2C423DC0-4FE4-4E5A-9386-412DE4FB2587