LWN.net Logo

wordpress: multiple vulnerabilities

Package(s):wordpress CVE #(s):CVE-2011-0700 CVE-2011-0701
Created:March 11, 2011 Updated:September 18, 2012
Description: From the Debian advisory:

CVE-2011-0700: Input passed via the post title when performing a "Quick Edit" or "Bulk Edit" action and via the "post_status", "comment_status", and "ping_status" parameters is not properly sanitised before being used. Certain input passed via tags in the tags meta-box is not properly sanitised before being returned to the user.

CVE-2011-0701: Wordpress incorrectly enforces user access restrictions when accessing posts via the media uploader and can be exploited to disclose the contents of e.g. private or draft posts.

Alerts:
Fedora FEDORA-2011-3746 2011-03-21
Fedora FEDORA-2011-3738 2011-03-21
Debian DSA-2190-1 2011-03-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds