CVE-2021-29450
Summary
| CVE | CVE-2021-29450 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-15 22:15:00 UTC |
| Updated | 2021-04-23 14:47:00 UTC |
| Description | Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges. This has been patched in WordPress 5.7.1, along with the older affected versions via minor releases. It's strongly recommended that you keep auto-updates enabled to receive the fix. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2630-1] wordpress security update |
MLIST |
lists.debian.org |
|
| Debian -- Security Information -- DSA-4896-1 wordpress |
DEBIAN |
www.debian.org |
|
| News – Security – WordPress.org |
MISC |
wordpress.org |
|
| WordPress: Authenticated disclosure of password-protected posts and pages · Advisory · WordPress/wordpress-develop · GitHub |
CONFIRM |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178554 Debian Security Update for wordpress (DLA 2630-1)
- 178560 Debian Security Update for wordpress (DSA 4896-1)
- 180560 Debian Security Update for wordpress (CVE-2021-29450)
- 730052 WordPress Prior to 5.7.1 Multiple Vulnerabilities