WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 treats unattached attachments as published, which might allow remote attackers to obtain sensitive data via vectors related to wp-includes/post.php.

http://www.cvedetails.com/cve/CVE-2011-3128/

This vulnerability affects the following application versions:

  • WordPress 3.0
  • WordPress 3.0.1
  • WordPress 3.0.2
  • WordPress 3.0.3
  • WordPress 3.0.4

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *