CVE-2006-6016: Medium severity wordpress wordpress vulnerability
Published Nov 21, 2006
·Updated
wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary user via a modified userid parameter.
Affected Software
1 affected component
WordPress<=2.0.4
Remediation
Patch Available
Event History
Nov 21, 2006
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
via NVD·11:07 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-6016?
CVE-2006-6016 has been assigned a medium severity rating due to the potential for unauthorized metadata access.
2
How do I fix CVE-2006-6016?
To fix CVE-2006-6016, upgrade your WordPress installation to version 2.0.5 or later.
3
Who is affected by CVE-2006-6016?
CVE-2006-6016 affects remote authenticated users of WordPress versions prior to 2.0.5.
4
What is the impact of CVE-2006-6016?
The impact of CVE-2006-6016 allows attackers to read sensitive metadata from arbitrary user accounts.
5
Is there a workaround for CVE-2006-6016?
There is no specific workaround for CVE-2006-6016; the best practice is to update to the secure version of WordPress.