CVE-2010-5106Wordpress vulnerability

CWE-2644 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
0.3%
top 46.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 14
Latest updateMay 17

Description

The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/wordpress< wordpress 3.0.3-1 (bookworm)
Debianwordpress/wordpress< 3.0.3-1+3
NVDwordpress/wordpress3.0.2+67

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2w3h-g44g-mrhv: The XML-RPC remote publishing interface in xmlrpc2022-05-17
OSV
CVE-2010-5106: The XML-RPC remote publishing interface in xmlrpc2012-09-14

📋Vendor Advisories

1
Debian
CVE-2010-5106: wordpress - The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 ...2010
CVE-2010-5106 — Debian Wordpress vulnerability | cvebase