PT-2019-5224 · WordPress · Wordpress

Nguyen The Duc

·

Published

2019-09-11

·

Updated

2023-01-20

·

CVE-2019-20043

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions WordPress versions 3.7 through 5.3.0
Description The issue is related to an authentication error in the class-wp-rest-posts-controller function of the WordPress content management system, allowing users to mark posts as sticky via the REST API. This could be exploited by a remote attacker to impact data integrity. Authenticated users without the rights to publish a post, such as those with the contributor role, could bypass restrictions and mark posts as sticky or unsticky.
Recommendations For WordPress versions 3.7 through 5.3.0, update to version 5.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST API endpoint related to post management until the update is applied.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2020-01953
CVE-2019-20043
DSA-4599-1
DSA-4677-1
GHSA-G7RG-HCHX-C2GW

Affected Products

Wordpress