First published: Mon Mar 14 2011(Updated: )
wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | <=3.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0701 is considered a moderate severity vulnerability affecting WordPress versions prior to 3.0.5.
To fix CVE-2011-0701, update your WordPress installation to version 3.0.5 or higher.
CVE-2011-0701 affects remote authenticated users of WordPress who can manipulate the attachment_id parameter.
CVE-2011-0701 allows remote authenticated users to read draft and private posts.
CVE-2011-0701 was disclosed in February 2011.