VDB
CVE-2019-20043
CVE-2019-20043
PUBLISHED
CVSS 4.300000190734863 MEDIUM
In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
EPSS 2.47% · 83.4th percentile
Risk Scores
CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS Score
2.47%
83.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | wordpress | *, 0, 4.8.3+dfsg-1 |
| Ubuntu:16.04:LTS | wordpress | 0, 4.3.1+dfsg-1, 4.4+dfsg-1 |
Timeline
- Dec 27, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 7, 2022 EPSS Score
- Jan 9, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-20043 third-party-advisory
- https://core.trac.wordpress.org/changeset/46893/trunk third-party-advisory
- https://github.com/WordPress/wordpress-develop/commit/1d1d5be7aa94608c04516cac4238e8c22b93c1d9 third-party-advisory
- https://wordpress.org/news/2019/12/wordpress-5-3-1-security-and-maintenance-release/ third-party-advisory
- https://wpvulndb.com/vulnerabilities/9973 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-20043 third-party-advisory