'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:WordPress REST API Type Juggling Vulnerability Exploit
Severity:high
CVE ID:
| Descripiton:
|
A privilege escalation vulnerability exists in WordPress. WordPress casts the ID parameter to an integer before passing it to get_post. This leads to type-juggling issue , it is then possible for an attacker to change the content of any post or page on a victim's site. From there, they can add plugin-specific shortcodes to exploit vulnerabilities, infect the site content with an SEO spam campaign, or inject ads, etc. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.