PT-2017-16615 · Debian+1 · Debian+1

Marc-Alexandre Montpas

·

Published

2017-01-30

·

Updated

2019-03-19

·

CVE-2017-5610

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WordPress versions prior to 4.7.2 Debian (affected versions not specified)
Description The issue concerns a problem with access restrictions in WordPress, specifically in the Press This feature. It allows remote attackers to bypass intended access restrictions by reading terms due to improper restriction of visibility of a taxonomy-assignment user interface.
Recommendations For WordPress versions prior to 4.7.2, update to version 4.7.2 or later to resolve the issue. For Debian, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-5610
DLA-813-1
DSA-3779-1

Affected Products

Debian
Wordpress