CVE-2010-5296: Medium severity wordpress vulnerability
wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the deleteusers capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-5296?
CVE-2010-5296 is a medium-severity vulnerability as it allows authenticated users to delete other users without proper permissions.
How do I fix CVE-2010-5296?
To fix CVE-2010-5296, update WordPress to version 3.0.2 or later.
Which WordPress versions are affected by CVE-2010-5296?
WordPress versions prior to 3.0.2, including all versions from 2.0 to 3.0.1, are affected by CVE-2010-5296.
What does CVE-2010-5296 exploit?
CVE-2010-5296 exploits improper access control for the delete_users capability within a WordPress Multisite configuration.
Who is at risk due to CVE-2010-5296?
Remote authenticated administrators of WordPress sites running affected versions are at risk due to CVE-2010-5296.