QID 150434
Date Published: 2021-12-04
QID 150434: WordPress Private Post Information Disclosure Vulnerability (CVE-2021-39203)
WordPress is an open-source blogging tool and content management system based on PHP and MySQL. It has many features including a plug-in architecture and a template system.
In affected versions of WordPress CMS authenticated users who don't have permission to view private post types/data can bypass restrictions in the block editor under certain conditions.
Affected versions:
WordPress 5.8 beta 1
Successful exploitation would lead attackers to enumerate private post data, which can help the attacker carry out further attacks and obtain sensitive information.
Solution
Customers are advised to upgrade to a fixed version WordPress 5.8 or later versions to remediate this vulnerability.
Vendor References
CVEs related to QID 150434
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WordPress |
|