First published: Mon Jan 30 2017(Updated: )
wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | <=4.7.1 | |
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5610 has been classified as a medium severity vulnerability.
To fix CVE-2017-5610, upgrade WordPress to version 4.7.2 or later.
CVE-2017-5610 allows remote attackers to bypass access restrictions and read taxonomy terms.
CVE-2017-5610 affects WordPress versions prior to 4.7.2.
There is no documented workaround for CVE-2017-5610, so upgrading is recommended.