QID 154112
Date Published: 2022-05-20
QID 154112: WordPress Disclosure of Password-Protected Page/Post Comments Vulnerability (CVE-2020-25286)
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database.
In wp-includes/comment-template.php, comments from a post or page could sometimes be seen in the latest comments even if the post or page was not public.
Affected Versions:
WordPress versions prior to 5.4.2
QID Detection Logic:
This QID checks for vulnerable version of WordPress installed on the target.
The manipulation as part of a Comment leads to a information disclosure vulnerability.
Solution
Upgrade the WordPress to new version.
Vendor References
CVEs related to QID 154112
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WordPress |
|