CVE-2017-1001000

The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identifier, which allows remote attackers to modify arbitrary pages via a request for wp-json/wp/v2/posts followed by a numeric value and a non-numeric value, as demonstrated by the wp-json/wp/v2/posts/123?id=123helloworld URI.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:wordpress:wordpress:4.7.1:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:4.7.2:*:*:*:*:*:*:*
cpe:2.3:a:wordpress:wordpress:4.7:*:*:*:*:*:*:*

Information

Published : 2017-04-02 18:59

Updated : 2019-10-02 17:03


NVD link : CVE-2017-1001000

Mitre link : CVE-2017-1001000


JSON object : View

Advertisement

dedicated server usa

Products Affected

wordpress

  • wordpress