CVE-2019-20043
Summary
| CVE | CVE-2019-20043 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-27 08:15:00 UTC |
| Updated | 2023-01-20 16:11:00 UTC |
| Description | In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Wordpress | Wordpress | All | All | All | All |
| Application | Wordpress | Wordpress | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Ensure that a user can publish_posts before making a post sticky. · WordPress/wordpress-develop@1d1d5be · GitHub | MISC | github.com | Third Party Advisory |
| Users without "publish_posts" rights can mark sticky/unsticky a post via REST API · Advisory · WordPress/wordpress-develop · GitHub | CONFIRM | github.com | |
| Debian -- Security Information -- DSA-4677-1 wordpress | DEBIAN | www.debian.org | |
| Changeset 46893 for trunk – WordPress Trac | MISC | core.trac.wordpress.org | Patch |
| News – WordPress 5.3.1 Security and Maintenance Release – WordPress.org | MISC | wordpress.org | Release Notes, Vendor Advisory |
| Debian -- Security Information -- DSA-4599-1 wordpress | DEBIAN | www.debian.org | |
| Bugtraq: [SECURITY] [DSA 4599-1] wordpress security update | BUGTRAQ | seclists.org | |
| WordPress <= 5.3 - Improper Access Controls in REST API | MISC | wpvulndb.com | Release Notes, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.