CVE-2007-1893: Medium severity WordPress vulnerability
xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated users with the contributor role to bypass intended access restrictions and invoke the publishposts functionality, which can be used to "publish a previously saved post."
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1893?
CVE-2007-1893 is classified as a high severity vulnerability due to its potential to allow unauthorized publishing of posts.
How do I fix CVE-2007-1893?
To fix CVE-2007-1893, it is recommended to upgrade to a later version of WordPress that addresses this vulnerability.
Who is affected by CVE-2007-1893?
CVE-2007-1893 affects remote authenticated users with the contributor role in WordPress versions up to 2.1.2.
What functionality can be exploited in CVE-2007-1893?
CVE-2007-1893 allows contributors to bypass access restrictions and invoke the publish_posts functionality.
Is CVE-2007-1893 still a risk for current WordPress installations?
CVE-2007-1893 is not a risk for current WordPress installations if they have been updated beyond version 2.1.2.