PT-2019-5224 · WordPress · Wordpress
Nguyen The Duc
·
Published
2019-09-11
·
Updated
2023-01-20
·
CVE-2019-20043
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
WordPress versions 3.7 through 5.3.0
Description
The issue is related to an authentication error in the
class-wp-rest-posts-controller function of the WordPress content management system, allowing users to mark posts as sticky via the REST API. This could be exploited by a remote attacker to impact data integrity. Authenticated users without the rights to publish a post, such as those with the contributor role, could bypass restrictions and mark posts as sticky or unsticky.Recommendations
For WordPress versions 3.7 through 5.3.0, update to version 5.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the REST API endpoint related to post management until the update is applied.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordpress