-

CVE-2019-16788

Users without "publish_posts" rights can mark sticky/unsticky a post via REST API

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-20043. Reason: This candidate is a duplicate of CVE-2019-20043. Notes: All CVE users should reference CVE-2019-20043 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
Mögliche Gegenmaßnahme
WordPress Core: Install latest version
WordPress Core: Install latest version
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
System
≫
Produkt WordPress Core
Version >= 0.0.0, < 4.7.16
Version >= 4.8.0, < 4.8.12
Version >= 4.9.0, < 4.9.13
Version >= 5.0.0, < 5.0.8
Version >= 5.1.0, < 5.1.4
Version >= 5.2.0, < 5.2.5
Version >= 5.3.0, < 5.3.1
System
≫
Produkt WordPress Core
Version >= 0.0.0, < 4.7.16
Version >= 4.8.0, < 4.8.12
Version >= 4.9.0, < 4.9.13
Version >= 5.0.0, < 5.0.8
Version >= 5.1.0, < 5.1.4
Version >= 5.2.0, < 5.2.5
Version >= 5.3.0, < 5.3.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.639
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-g7rg-hchx-c2gw
Third Party Advisory