CVE-2021-39203: fallo de gravedad media en wordpress-develop
Private data disclosure/privilege escalation through the block editor in Wordpress
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.8epss 0.9%
probabilidad de explotación
0.9%top 40% de las CVE
explotación observada
noninguna fuente lo reporta
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authenticated users who don't have permission to view private post types/data can bypass restrictions in the block editor under certain conditions. This affected WordPress 5.8 beta during the testing period. It's fixed in the final 5.8 release.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Productos afectados
WordPress · wordpress-developCVEs relacionadas — wordpress-develop
En el mismo producto, de las más peligrosas a las menos.
CVE-2022-21661HIGHSQL injection in WordPressEPSS 97.8%CVE-2021-29447HIGHWordPress Authenticated XXE attack when installation is running PHP 8EPSS 85.7%CVE-2022-21662HIGHStored XSS in WordPressEPSS 64.5%CVE-2022-21664HIGHSQL injection in WordPressEPSS 3.8%CVE-2022-21663MEDIUMAuthenticated Object Injection in Multisites in WordPressEPSS 3.7%CVE-2020-4047MEDIUMAuthenticated XSS via media attachment page in WordPressEPSS 3.3%