CVE-2017-5610: Infoleak
wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/press-this (wp-admin/includes/class-wp-press-this.php)to a version that resolves this vulnerability.Fixed in 4.7.2
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5610?
CVE-2017-5610 has been classified as a medium severity vulnerability.
How do I fix CVE-2017-5610?
To fix CVE-2017-5610, upgrade WordPress to version 4.7.2 or later.
What type of attack is possible with CVE-2017-5610?
CVE-2017-5610 allows remote attackers to bypass access restrictions and read taxonomy terms.
Which versions of WordPress are affected by CVE-2017-5610?
CVE-2017-5610 affects WordPress versions prior to 4.7.2.
Is there a workaround for CVE-2017-5610 if I cannot upgrade?
There is no documented workaround for CVE-2017-5610, so upgrading is recommended.