{"api_version":"1","generated_at":"2026-07-24T19:43:47+00:00","cve":"CVE-2019-20043","urls":{"html":"https://cve.report/CVE-2019-20043","api":"https://cve.report/api/cve/CVE-2019-20043.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-20043","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-20043"},"summary":{"title":"CVE-2019-20043","description":"In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-12-27 08:15:00","updated_at":"2023-01-20 16:11:00"},"problem_types":["CWE-269"],"metrics":[],"references":[{"url":"https://github.com/WordPress/wordpress-develop/commit/1d1d5be7aa94608c04516cac4238e8c22b93c1d9","name":"https://github.com/WordPress/wordpress-develop/commit/1d1d5be7aa94608c04516cac4238e8c22b93c1d9","refsource":"MISC","tags":["Third Party Advisory"],"title":"Ensure that a user can publish_posts before making a post sticky. · WordPress/wordpress-develop@1d1d5be · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-g7rg-hchx-c2gw","name":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-g7rg-hchx-c2gw","refsource":"CONFIRM","tags":[],"title":"Users without \"publish_posts\" rights can mark sticky/unsticky a post via REST API · Advisory · WordPress/wordpress-develop · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.debian.org/security/2020/dsa-4677","name":"DSA-4677","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-4677-1 wordpress","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://core.trac.wordpress.org/changeset/46893/trunk","name":"https://core.trac.wordpress.org/changeset/46893/trunk","refsource":"MISC","tags":["Patch"],"title":"Changeset 46893 for trunk – WordPress Trac","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"https://wordpress.org/news/2019/12/wordpress-5-3-1-security-and-maintenance-release/","name":"https://wordpress.org/news/2019/12/wordpress-5-3-1-security-and-maintenance-release/","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"News – WordPress 5.3.1 Security and Maintenance Release – WordPress.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.debian.org/security/2020/dsa-4599","name":"DSA-4599","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-4599-1 wordpress","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://seclists.org/bugtraq/2020/Jan/8","name":"20200108 [SECURITY] [DSA 4599-1] wordpress security update","refsource":"BUGTRAQ","tags":[],"title":"Bugtraq: [SECURITY] [DSA 4599-1] wordpress security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://wpvulndb.com/vulnerabilities/9973","name":"https://wpvulndb.com/vulnerabilities/9973","refsource":"MISC","tags":["Release Notes","Third Party Advisory"],"title":"WordPress <= 5.3 - Improper Access Controls in REST API","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-20043","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-20043","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"20043","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"10.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"20043","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"20043","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wordpress","cpe5":"wordpress","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"20043","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wordpress","cpe5":"wordpress","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-20043","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://wpvulndb.com/vulnerabilities/9973","url":"https://wpvulndb.com/vulnerabilities/9973"},{"url":"https://wordpress.org/news/2019/12/wordpress-5-3-1-security-and-maintenance-release/","refsource":"MISC","name":"https://wordpress.org/news/2019/12/wordpress-5-3-1-security-and-maintenance-release/"},{"url":"https://core.trac.wordpress.org/changeset/46893/trunk","refsource":"MISC","name":"https://core.trac.wordpress.org/changeset/46893/trunk"},{"url":"https://github.com/WordPress/wordpress-develop/commit/1d1d5be7aa94608c04516cac4238e8c22b93c1d9","refsource":"MISC","name":"https://github.com/WordPress/wordpress-develop/commit/1d1d5be7aa94608c04516cac4238e8c22b93c1d9"},{"refsource":"BUGTRAQ","name":"20200108 [SECURITY] [DSA 4599-1] wordpress security update","url":"https://seclists.org/bugtraq/2020/Jan/8"},{"refsource":"DEBIAN","name":"DSA-4599","url":"https://www.debian.org/security/2020/dsa-4599"},{"refsource":"CONFIRM","name":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-g7rg-hchx-c2gw","url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-g7rg-hchx-c2gw"},{"refsource":"DEBIAN","name":"DSA-4677","url":"https://www.debian.org/security/2020/dsa-4677"}]}},"nvd":{"publishedDate":"2019-12-27 08:15:00","lastModifiedDate":"2023-01-20 16:11:00","problem_types":["CWE-269"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7","versionEndExcluding":"5.3.1","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"20043","Ordinal":"163869","Title":"CVE-2019-20043","CVE":"CVE-2019-20043","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"20043","Ordinal":"1","NoteData":"In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"20043","Ordinal":"2","NoteData":"2019-12-27","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"20043","Ordinal":"3","NoteData":"2020-05-06","Type":"Other","Title":"Modified"}]}}}