CVE-2010-5106: Medium severity WordPress vulnerability
The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticated users to bypass intended access restrictions, and publish, edit, or delete posts, by leveraging the Author or Contributor role.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-5106?
CVE-2010-5106 has a high severity rating as it allows unauthorized publishing and editing of posts by exploiting a capability check flaw.
How do I fix CVE-2010-5106?
To fix CVE-2010-5106, upgrade to WordPress version 3.0.3 or later, which includes the necessary security patch.
Which versions of WordPress are affected by CVE-2010-5106?
CVE-2010-5106 affects multiple versions of WordPress, specifically all versions prior to 3.0.3.
What types of attacks can CVE-2010-5106 enable?
CVE-2010-5106 can enable attacks that allow unauthorized users to publish, edit, or delete posts on WordPress sites.
Who is impacted by CVE-2010-5106?
Users with the Author or Contributor role on WordPress sites prior to version 3.0.3 are impacted by CVE-2010-5106.