← Back to CVE List
WORDFENCE-8b8d4431-ac72-45a2-b4a1-19690946d0eeWordfence
Vulnerability Summary
WordPress Core is vulnerable to Missing Authorization via the REST comments controller update_item_permissions_check() in various versions up to, and including, 7.1 because the target post is not authorized when a comment or note's parent post is changed - only the current parent was checked. This makes it possible for an authenticated attacker who can edit a comment (e.g. an Author editing a comment on their own post) to reparent it onto an arbitrary post, including posts they can neither read nor edit.
CVSS v3.1 Base Metrics — Score 4.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityLow
AvailabilityNone
Affected & Patched Versions
- WordPress * - 6.6.7
- WordPress 6.7 - 6.7.7
- WordPress 6.8 - 6.8.8
- WordPress 6.9 - 6.9.7
- WordPress 7.0 - 7.0.4
- WordPress 7.1 - 7.1
- WordPress 1