CVE-2015-5623
EPSS 8.8%
描述
WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.
如何修補 CVE-2015-5623
要修補 CVE-2015-5623,請將受影響套件升級到下列已修補版本。
- Debian/wordpress—升級至 4.2.3+dfsg-1 或更新版本
CVE-2015-5623 正在被利用嗎?
中等 — EPSS 為 8.8%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 4.2.3+dfsg-1