Related Vulnerabilities: CVE-2020-28035  

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

Severity High

Remote Yes

Type Privilege escalation

Description

WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

AVG-1257 wordpress 5.5.1-1 5.5.3-1 Critical Fixed

03 Nov 2020 ASA-202011-3 AVG-1257 wordpress Critical multiple issues

https://github.com/WordPress/wordpress-develop/commit/2d677cd4b2e24d0b5f17a3a278c719051bbe8e35