wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://core.trac.wordpress.org/ticket/13887 | patch exploit |
https://core.trac.wordpress.org/changeset/16637 | patch exploit |
http://codex.wordpress.org/Version_3.0.2 | patch vendor advisory |