cbcvebase.
CVE-2016-10148
published 2017-01-18

CVE-2016-10148: The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the…

PriorityP421medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
1.64%
73.7th percentile
The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-access restrictions via the plugin parameter to wp-admin/admin-ajax.php, a related issue to CVE-2016-6896.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianwordpress< wordpress 4.6.1+dfsg-1 (bookworm)wordpress 4.6.1+dfsg-1 (bookworm)
wordpresswordpress<= 4.5.5
wordpresswordpress>= 0 < 4.6.1+dfsg-14.6.1+dfsg-1
wordpresswordpress>= 0 < 4.6.1+dfsg-14.6.1+dfsg-1
wordpresswordpress>= 0 < 4.6.1+dfsg-14.6.1+dfsg-1
wordpresswordpress>= 0 < 4.6.1+dfsg-14.6.1+dfsg-1

CVSS provenance

nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.