Hello there,
I found a bug/issue with WordPress last update. Anyone who is registered as contributor can easily able to publish a post.
I've seen many blogs has been infected with this.
Here is one of that blog - [Link removed]
Thanks.
Hello there,
I found a bug/issue with WordPress last update. Anyone who is registered as contributor can easily able to publish a post.
I've seen many blogs has been infected with this.
Here is one of that blog - [Link removed]
Thanks.
If you think you've found a security problem in WordPress, please see the Security FAQ for information on reporting the problem.
Can't reproduce, but would appreciate an email to security@wordpress.org if you think you can.
I've sent an email to security@wordpress.org.
Though here is an article about that contributor post issue.
http://hellboundbloggers.com/2011/02/16/wordpress-contributor-post-submission-vulnerability-alert/
Wasn't this fixed in 3.0.5 version?
Two moderate security issues were fixed that could have allowed a Contributor- or Author-level user to gain further access to the site.
Most likely not, but it's possible.
I'm closing this thread as it should be handled through proper channels. A note, emailing security@, but then publishing a thread that has nothing to back up your claims, goes against the concept of responsible disclosure. We have this procedure in place in part to prevent panic and in-the-wild 0day exploits (which I don't think this is currently).
This vulnerability was fixed in WordPress 3.1.2.
This topic has been closed to new replies.