wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://codex.wordpress.org/Version_4.7.2 | release notes vendor advisory |
http://www.securityfocus.com/bid/95816 | third party advisory vdb entry |
http://www.debian.org/security/2017/dsa-3779 | third party advisory vendor advisory |
http://www.openwall.com/lists/oss-security/2017/01/28/5 | patch mailing list third party advisory |
https://github.com/WordPress/WordPress/commit/21264a31e0849e6ff793a06a17de877dd88ea454 | third party advisory patch |
https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/ | patch vendor advisory |
https://wpvulndb.com/vulnerabilities/8729 | third party advisory patch |
http://www.securitytracker.com/id/1037731 | third party advisory vdb entry |