CVE-2016-10983: Medium severity ghost foundation ghost vulnerability
Published Sep 17, 2019
·Updated
The ghost plugin before 0.5.6 for WordPress has no access control for wp-admin/tools.php?ghostexport=true downloads of exported data.
Affected Software
1 affected component
Ghost Ghost Wordpress<0.5.6
Event History
Sep 17, 2019
CVE Published
via MITRE·02:21 PM
Data Sourced
via MITRE·02:21 PM
Description
Frequently Asked Questions
1
What is CVE-2016-10983?
CVE-2016-10983 is a vulnerability in the ghost plugin before 0.5.6 for WordPress.
2
What is the severity of CVE-2016-10983?
The severity of CVE-2016-10983 is medium with a CVSS score of 6.5.
3
How does CVE-2016-10983 affect WordPress?
CVE-2016-10983 affects WordPress websites that have the ghost plugin installed and running a version prior to 0.5.6.
4
What is the impact of CVE-2016-10983?
CVE-2016-10983 allows unauthorized users to download exported data without proper access control in the wp-admin/tools.php?ghostexport=true endpoint.
5
How can I fix CVE-2016-10983?
To fix CVE-2016-10983, update the ghost plugin to version 0.5.6 or later.