WordPress Vulnerabilities
WordPress <= 5.3 - Authenticated Improper Access Controls in REST API
Description
An unprivileged user could make a post sticky via the REST API. Authenticated users who do not have the rights to publish a post were able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that.
Affects WordPress
References
Classification
Type
PRIVESC
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Daniel Bachhuber
Verified
No
WPVDB ID
Timeline
Publicly Published
2019-12-13 (about 6 years ago)
Added
2019-12-13 (about 6 years ago)
Last Updated
2020-12-15 (about 5 years ago)