RETIRED: WordPress Unspecified Unauthorized Access Vulnerability
BID:48511
Info
RETIRED: WordPress Unspecified Unauthorized Access Vulnerability
| Bugtraq ID: | 48511 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2011 12:00AM |
| Updated: | Jul 04 2011 10:00PM |
| Credit: | K. Gudinavicius, SEC Consult |
| Vulnerable: |
WordPress WordPress 3.1.3 |
| Not Vulnerable: |
WordPress WordPress 3.1.4 |
Discussion
RETIRED: WordPress Unspecified Unauthorized Access Vulnerability
WordPress is prone to an unauthorized-access vulnerability.
An attacker can exploit this issue to gain unauthorized access to arbitrary user accounts.
WordPress 3.1.3 is vulnerable; other versions may also be affected.
RETIRED: This BID is retired because it is a duplicate of BID 48521.
WordPress is prone to an unauthorized-access vulnerability.
An attacker can exploit this issue to gain unauthorized access to arbitrary user accounts.
WordPress 3.1.3 is vulnerable; other versions may also be affected.
RETIRED: This BID is retired because it is a duplicate of BID 48521.
Exploit / POC
RETIRED: WordPress Unspecified Unauthorized Access Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
RETIRED: WordPress Unspecified Unauthorized Access Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
RETIRED: WordPress Unspecified Unauthorized Access Vulnerability
References:
References:
- Wordpress Homepage (Wordpress)
- WordPress 3.1.4 (and 3.2 Release Candidate 3) (WordPress)