CVE-2009-2854: Medium severity wordpress vulnerability
Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7) export.php, (8) import.php, or (9) link-add.php in wp-admin/.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2854?
The severity of CVE-2009-2854 is considered medium as it allows unauthorized remote edits or additions.
How do I fix CVE-2009-2854?
To fix CVE-2009-2854, update your WordPress installation to version 2.8.3 or later.
What actions can attackers perform due to CVE-2009-2854?
Attackers can make unauthorized edits or additions to comments, pages, categories, and links.
Which versions of WordPress are affected by CVE-2009-2854?
CVE-2009-2854 affects all WordPress versions prior to 2.8.3.
Is there a patch for CVE-2009-2854?
Yes, a security release is available that addresses the vulnerabilities mentioned in CVE-2009-2854.