In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users...
Vulnerability Description
In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-20043
Credits & Attribution
No credits recorded in the NVD database.
References
- https://wpvulndb.com/vulnerabilities/9973
- https://wordpress.org/news/2019/12/wordpress-5-3-1-security-and-maintenance-release/
- https://core.trac.wordpress.org/changeset/46893/trunk
- https://github.com/WordPress/wordpress-develop/commit/1d1d5be7aa94608c04516cac4238e8c22b93c1d9
- https://seclists.org/bugtraq/2020/Jan/8
- https://www.debian.org/security/2020/dsa-4599
- https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-g7rg-hchx-c2gw
- https://www.debian.org/security/2020/dsa-4677
More from wordpress
View All →Affected Vendor
wordpress
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.