WordPress Core 2.3.1 - Unauthorized Post Access

EDB-ID:

30889

CVE:





Platform:

PHP

Date:

2007-12-15


source: https://www.securityfocus.com/bid/26885/info

WordPress is prone to a vulnerability that lets unauthorized users read draft posts before they have been published.

This issue affects WordPress 2.3.1; other versions may also be affected.

NOTE: This BID is being reinstated because further investigation reveals that the application is vulnerable. The exploit URI supplied in the initial report was not sufficient to trigger the issue, which led to the vulnerability claim being refuted. However, follow-up information from the reporter included a URI that does trigger the issue.

http://www.example.com/wordpress/index.php/wp-admin/