← Back to CVE List
WORDFENCE-28747e2e-9012-470c-a891-0fe97fd1ddbaWordfence
Vulnerability Summary
WordPress Core is vulnerable to an authorization bypass via the XML-RPC _insert_post() handler in various versions up to, and including, 7.1 due to internal-only builtin post types such as customize_changeset being writable through the generic post API, bypassing the customizer's per-setting capability enforcement (notably edit_css/unfiltered_css). A user who can create changesets but lacks edit_css can write changeset values including Additional CSS.
CVSS v3.1 Base Metrics — Score 5.5 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
ScopeChanged
ConfidentialityLow
IntegrityLow
AvailabilityNone
Affected & Patched Versions
- WordPress * - 6.6.7
- WordPress 6.7 - 6.7.7
- WordPress 6.8 - 6.8.8
- WordPress 6.9 - 6.9.7
- WordPress 7.0 - 7.0.4
- WordPress 7.1 - 7.1
- WordPress 1