CVE-2009-2853: Critical severity wordpress vulnerability
Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2853?
CVE-2009-2853 is considered a high severity vulnerability as it allows remote attackers to gain privileges.
How do I fix CVE-2009-2853?
To fix CVE-2009-2853, it is recommended to upgrade to WordPress version 2.8.3 or later.
Which versions of WordPress are affected by CVE-2009-2853?
CVE-2009-2853 affects multiple versions of WordPress prior to 2.8.3 including releases from 0.71 to 2.8.2.
What types of requests can expose the vulnerability in CVE-2009-2853?
CVE-2009-2853 can be exploited through direct requests to specific scripts such as admin-footer.php and edit-category-form.php.
Are there known exploits for CVE-2009-2853?
Yes, there are known exploits for CVE-2009-2853 that could allow attackers to change user roles and gain unauthorized access.