CVE-2010-5106
The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the…
Does this matter?
Lower severity and a low EPSS score (2.18%). Track it; it rarely justifies an emergency change on its own.
Description
The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 2.18% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- wordpress/wordpress
- Source
- secalert@redhat.com
References
- http://codex.wordpress.org/Version_3.0.3
- http://core.trac.wordpress.org/changeset/16803Exploit, Patch
- http://openwall.com/lists/oss-security/2012/09/14/10
- http://codex.wordpress.org/Version_3.0.3
- http://core.trac.wordpress.org/changeset/16803Exploit, Patch
- http://openwall.com/lists/oss-security/2012/09/14/10
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.