#VU5510 Improper access control in WordPress - CVE-2017-5610
Published: January 30, 2017 / Updated: January 30, 2017
WordPress
WordPress.ORG
Description
The vulnerability allows a remote attacker to gain access to otherwise restricted information.
The vulnerability resides within wp-admin/includes/class-wp-press-this.php script in Press This functionality, which does not properly restrict visibility permissions to user interface for assigning taxonomy terms. A remote authenticated attacker may be able to gain access to potentially sensitive information.