VDB
CVE-2010-0682
CVE-2010-0682
PUBLISHED
CVSS 4 MEDIUM
WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.
EPSS 24.99% · 96.3th percentile
Risk Scores
CVSS 2.0
4
EPSS Score
24.99%
96.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| wordpress | wordpress | 2.9.1, 2.9.1, 2.9.1 |
Timeline
- Feb 13, 2010 PoC Published
- Feb 23, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- FEDORA-2010-19329 vendor-advisory
- http://tmacuk.co.uk/?p=180 url
- http://wordpress.org/development/2010/02/wordpress-2-9-2/ url
- 42871 third-party-advisory
- http://hakre.wordpress.com/2010/02/16/the-short-memory-of-wordpress-org-security/ url
- https://core.trac.wordpress.org/ticket/11236 url
- 38592 third-party-advisory
- FEDORA-2010-19330 vendor-advisory
- 62330 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2010-0682 advisory
- http://hakre.wordpress.com/2010/02/16/the-short-memory-of-wordpress-org-security url
- http://wordpress.org/development/2010/02/wordpress-2-9-2 url