Improper access control in WordPress - CVE-2020-28036
Published: November 2, 2020 / Updated: November 9, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in wp-includes/class-wp-xmlrpc-server.php. A remote attacker can bypass implemented security restrictions and gain unauthorized access to the application by using XML-RPC to comment on a post.
Affected software
Arch Linux
Fedora
wordpress (Debian package)
wordpress
How to mitigate CVE-2020-28036
wordpress (Debian package) - update to 5.0.11+dfsg1-0+deb10u1
wordpress - addressed in versions 5.1.8-1.el6, 5.1.8-1.el7, 5.5.3-1.fc31, 5.5.3-1.fc32, 5.5.3-1.fc33