4
CVSSv2

CVE-2011-0701

Published: 14/03/2011 Updated: 22/11/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

wp-admin/async-upload.php in the media uploader in WordPress prior to 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress

Vendor Advisories

Two XSS bugs and one potential information disclosure issue were discovered in WordPress, a weblog manager The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-0700 Input passed via the post title when performing a Quick Edit or Bulk Edit action and via the post_status, comment_status, and ping_status ...