CVE-2017-5610
published 2017-01-30CVE-2017-5610: wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user…
PriorityP335medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
5.06%
91.4th percentile
wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | wordpress | < wordpress 4.7.2+dfsg-1 (bookworm) | wordpress 4.7.2+dfsg-1 (bookworm) |
| wordpress | wordpress | <= 4.7.1 | — |
| wordpress | wordpress | >= 0 < 4.7.2+dfsg-1 | 4.7.2+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.7.2+dfsg-1 | 4.7.2+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.7.2+dfsg-1 | 4.7.2+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.7.2+dfsg-1 | 4.7.2+dfsg-1 |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WordPress up to 4.7.1 Press This class-wp-press-this.php information disclosure (FEDORA-2017-338a3f27e5 / Nessus ID 96965)
vuldb·2026-05-16·CVSS 5.3
CVE-2017-5610 [MEDIUM] WordPress up to 4.7.1 Press This class-wp-press-this.php information disclosure (FEDORA-2017-338a3f27e5 / Nessus ID 96965)
A vulnerability labeled as critical has been found in WordPress up to 4.7.1. This affects an unknown part of the file wp-admin/includes/class-wp-press-this.php of the component Press This. Executing a manipulation can lead to information disclosure.
The identification of this vulnerability is CVE-2017-5610. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
GHSA
GHSA-2wgv-28wx-hxv3: wp-admin/includes/class-wp-press-this
ghsa_unreviewed·2022-05-14
CVE-2017-5610 [MEDIUM] CWE-200 GHSA-2wgv-28wx-hxv3: wp-admin/includes/class-wp-press-this
wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.
OSV
CVE-2017-5610: wp-admin/includes/class-wp-press-this
osv·2017-01-30·CVSS 5.3
CVE-2017-5610 [MEDIUM] CVE-2017-5610: wp-admin/includes/class-wp-press-this
wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.
Debian
CVE-2017-5610: wordpress - wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7....
vendor_debian·2017·CVSS 5.3
CVE-2017-5610 [MEDIUM] CVE-2017-5610: wordpress - wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7....
wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.
Scope: local
bookworm: resolved (fixed in 4.7.2+dfsg-1)
bullseye: resolved (fixed in 4.7.2+dfsg-1)
forky: resolved (fixed in 4.7.2+dfsg-1)
sid: resolved (fixed in 4.7.2+dfsg-1)
trixie: resolved (fixed in 4.7.2+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2 [epel-all]
bugzilla·2017-01-27·CVSS 5.3
CVE-2017-5610 [MEDIUM] CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2 [epel-all]
CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2 [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2 [fedora-all]
bugzilla·2017-01-27·CVSS 5.3
CVE-2017-5610 [MEDIUM] CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2 [fedora-all]
CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple s
Bugzilla
CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2
bugzilla·2017-01-27·CVSS 5.3
CVE-2017-5610 [MEDIUM] CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2
CVE-2017-5610 CVE-2017-5611 CVE-2017-5612 wordpress: Multiple security fixes in 4.7.2
WordPress versions 4.7.1 and earlier are affected by three security issues:
1. The user interface for assigning taxonomy terms in Press This is shown to users who do not have permissions to use it.
2. WP_Query is vulnerable to a SQL injection (SQLi) when passing unsafe data. WordPress core is not directly vulnerable to this issue, but we’ve added hardening to prevent plugins and themes from accidentally causing a vulnerability.
3. A cross-site scripting (XSS) vulnerability was discovered in the posts list table.
External Reference:
https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/
Discussion:
Created wordpress tracking bugs for this issue:
Affects: fedora-all [bug 1417159]
Aff
http://www.debian.org/security/2017/dsa-3779http://www.openwall.com/lists/oss-security/2017/01/28/5http://www.securityfocus.com/bid/95816http://www.securitytracker.com/id/1037731https://codex.wordpress.org/Version_4.7.2https://github.com/WordPress/WordPress/commit/21264a31e0849e6ff793a06a17de877dd88ea454https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/https://wpvulndb.com/vulnerabilities/8729http://www.debian.org/security/2017/dsa-3779http://www.openwall.com/lists/oss-security/2017/01/28/5http://www.securityfocus.com/bid/95816http://www.securitytracker.com/id/1037731https://codex.wordpress.org/Version_4.7.2https://github.com/WordPress/WordPress/commit/21264a31e0849e6ff793a06a17de877dd88ea454https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/https://wpvulndb.com/vulnerabilities/8729
2017-01-30
Published