ThreatPress

WordPress Vulnerabilities Database

Back

WordPress <= 4.5.2 - Session Hijacking

Product
WordPress
Description
This vulnerability allows an attacker to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.
Solution
Update WordPress.
Classification
Type Session Hijacking
References
CVE Mitre
CVE
Name CVE-2016-5835
Versions
Affected In <= 4.5.2
Fixed In 4.5.3
Disclosure date
2016-06-23