Improper access control in WordPress - CVE-2019-20043
Published: December 13, 2019 / Updated: January 8, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php. A remote authenticated attacker can bypass implemented security restrictions and make a post sticky via the REST API.
Affected software
wordpress (Debian package)
How to mitigate CVE-2019-20043
wordpress (Debian package) - addressed in versions 4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u1, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1