ThreatPress

WordPress Vulnerabilities Database

Back

WordPress <= 2.1.2 - Security BYPASS

Product
WordPress
Description
The authenticated users with the contributor role can bypass intended access restrictions and invoke the publish_posts functionality.
Solution
Update the WordPress to the latest available version (at least 2.1.3).
Classification
Type BYPASS
References
CVE Mitre
CVE
Name CVE-2007-1893
Versions
Affected In <= 2.1.2
Fixed In 2.1.3
Disclosure date
2007-04-09
Credits
ryan
Submitter
ThreatPress