CVE-2007-1893
published 2007-04-09CVE-2007-1893: xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access…
PriorityP417medium4.9CVSS 2.0
AVAACMAuSCPIPAP
EPSS
1.17%
63.8th percentile
xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functionality, which can be used to "publish a previously saved post."
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 2.1.3-1 (bookworm) | wordpress 2.1.3-1 (bookworm) |
| wordpress | wordpress | <= 2.1.2 | — |
| wordpress | wordpress | >= 0 < 2.1.3-1 | 2.1.3-1 |
| wordpress | wordpress | >= 0 < 2.1.3-1 | 2.1.3-1 |
| wordpress | wordpress | >= 0 < 2.1.3-1 | 2.1.3-1 |
| wordpress | wordpress | >= 0 < 2.1.3-1 | 2.1.3-1 |
CVSS provenance
nvdv2.04.9MEDIUMAV:A/AC:M/Au:S/C:P/I:P/A:P
osv4.9MEDIUM
vendor_debian4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v744-f96h-39q4: xmlrpc (xmlrpc
ghsa_unreviewed·2022-05-01
CVE-2007-1893 [MEDIUM] GHSA-v744-f96h-39q4: xmlrpc (xmlrpc
xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functionality, which can be used to "publish a previously saved post."
OSV
CVE-2007-1893: xmlrpc (xmlrpc
osv·2007-04-09·CVSS 4.9
CVE-2007-1893 [MEDIUM] CVE-2007-1893: xmlrpc (xmlrpc
xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functionality, which can be used to "publish a previously saved post."
Debian
CVE-2007-1893: wordpress - xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote auth...
vendor_debian·2007·CVSS 4.9
CVE-2007-1893 [MEDIUM] CVE-2007-1893: wordpress - xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote auth...
xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publish_posts functionality, which can be used to "publish a previously saved post."
Scope: local
bookworm: resolved (fixed in 2.1.3-1)
bullseye: resolved (fixed in 2.1.3-1)
forky: resolved (fixed in 2.1.3-1)
sid: resolved (fixed in 2.1.3-1)
trixie: resolved (fixed in 2.1.3-1)
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/24751http://secunia.com/advisories/25108http://trac.wordpress.org/ticket/4091http://www.debian.org/security/2007/dsa-1285http://www.notsosecure.com/folder2/2007/04/03/wordpress-212-xmlrpc-security-issues/http://www.vupen.com/english/advisories/2007/1245https://exchange.xforce.ibmcloud.com/vulnerabilities/33470http://secunia.com/advisories/24751http://secunia.com/advisories/25108http://trac.wordpress.org/ticket/4091http://www.debian.org/security/2007/dsa-1285http://www.notsosecure.com/folder2/2007/04/03/wordpress-212-xmlrpc-security-issues/http://www.vupen.com/english/advisories/2007/1245https://exchange.xforce.ibmcloud.com/vulnerabilities/33470
2007-04-09
Published