PT-2008-5106 · WordPress · Wordpress

Hanno Böck

·

Published

2008-08-27

·

Updated

2017-08-08

·

CVE-2008-3747

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WordPress versions prior to 2.6.1
Description The issue concerns the get edit post link and get edit comment link functions in WordPress, which do not enforce SSL communication as intended. This could allow remote attackers to gain administrative access by intercepting cookies over the network.
Recommendations For versions prior to 2.6.1, update to version 2.6.1 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3747

Affected Products

Wordpress