#VU23574 Improper access control in WordPress - CVE-2019-20043
Published: December 13, 2019 / Updated: January 8, 2020
WordPress
WordPress.ORG
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php. A remote authenticated attacker can bypass implemented security restrictions and make a post sticky via the REST API.