CVE-2008-0664: Medium severity wordpress vulnerability
The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers to edit posts of other blog users via unknown vectors.
Other sources
WordPress 2.3.3 was released with following announcement:
WordPress 2.3.3 is an urgent security release. A flaw was found in our XML-RPC implementation such that a specially crafted request would allow any valid user to edit posts of any other user on that blog.
http://wordpress.org/development/2008/02/wordpress-233/
Upstream bug report: http://trac.wordpress.org/ticket/5313
Some PoCs are already available publicly: http://www.village-idiot.org/archives/2008/02/02/wordpress-232-exploit-confirmed/
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0664?
CVE-2008-0664 is classified as a critical vulnerability as it allows remote attackers to edit posts of other blog users.
How do I fix CVE-2008-0664?
To fix CVE-2008-0664, upgrade your WordPress installation to version 2.3.3 or later.
Which versions of WordPress are affected by CVE-2008-0664?
CVE-2008-0664 affects all WordPress versions prior to 2.3.3.
What type of attack does CVE-2008-0664 facilitate?
CVE-2008-0664 facilitates unauthorized post editing by remote attackers due to a flaw in the XML-RPC implementation.
Is CVE-2008-0664 a newly discovered vulnerability?
No, CVE-2008-0664 was reported in early 2008 and has since been addressed in updates.