'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:WordPress REST API Posts Controller Privilege Escalation Vulnerability
Severity:high
CVE ID:
| Descripiton:
|
A privilege escalation vulnerability exists in WordPress. The vulnerability is due to improper handling of post id's within the REST API posts controller. A remote, unauthenticated attacker could exploit this vulnerability by sending a crafted request to a vulnerable WordPress website. Successful exploitation of this vulnerability could lead to arbitrary modification of WordPress post content. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.