CVE-2010-0682: Medium severity WordPress vulnerability
Published Feb 23, 2010
·Updated
WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.
Affected Software
4 affected components
WordPress=2.9
WordPress=2.9.1
WordPress=2.9.1-beta1
WordPress=2.9.1-rc1
Remediation
Patch Available
Event History
Feb 23, 2010
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0682?
The severity of CVE-2010-0682 is considered moderate as it allows authenticated users to access private information.
2
How do I fix CVE-2010-0682?
To fix CVE-2010-0682, upgrade your WordPress installation to version 2.9.2 or later.
3
Which versions of WordPress are affected by CVE-2010-0682?
CVE-2010-0682 affects WordPress versions 2.9, 2.9.1, 2.9.1-beta1, and 2.9.1-rc1.
4
What type of vulnerability is CVE-2010-0682?
CVE-2010-0682 is a privilege escalation vulnerability that allows unauthorized access to trash posts.
5
Who is impacted by CVE-2010-0682?
Authenticated users in WordPress 2.9 and prior versions are impacted by CVE-2010-0682.