Vulnerability identifier: #VU151460
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to disclose URL slugs of draft and pending posts belonging to other users.
The vulnerability exists due to missing authorization in WordPress post access controls when accessing draft and pending posts. A remote user can discover URL slugs of draft and pending posts belonging to other users to disclose URL slugs of draft and pending posts belonging to other users.
Affected software
WordPress
Remediation
Install security update from vendor's website.
WordPress - addressed in versions 4.7.36, 4.8.31, 4.9.32, 5.0.28, 5.1.25, 5.2.27, 5.3.24, 5.4.22, 5.5.21, 5.6.20, 5.7.18, 5.8.16, 5.9.17, 6.0.15, 6.1.13, 6.2.12, 6.3.11, 6.4.11, 6.5.11, 6.6.8, 6.7.8, 6.8.9, 6.9.8, 7.0.5, 7.1.1
External References
Related Security Bulletins