VDB
CVE-2019-20043
CVE-2019-20043
PUBLISHED
In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
EPSS 1.17% · 79.0th percentile
Risk Scores
EPSS Score
1.17%
79.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | wordpress | *, 0, 4.8.3+dfsg-1 |
| Ubuntu:16.04:LTS | wordpress | 0, 4.3.1+dfsg-1, 4.4+dfsg-1 |
Exploit Intelligence
- https://wpvulndb.com/vulnerabilities/9973 (circl)
- https://wordpress.org/news/2019/12/wordpress-5-3-1-security-and-maintenance-release/ (circl)
- https://core.trac.wordpress.org/changeset/46893/trunk (circl)
- https://github.com/WordPress/wordpress-develop/commit/1d1d5be7aa94608c04516cac4238e8c22b93c1d9 (circl)
- 20200108 [SECURITY] [DSA 4599-1] wordpress security update (circl)
- DSA-4599 (circl)
- https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-g7rg-hchx-c2gw (circl)
- DSA-4677 (circl)
Timeline
- Dec 27, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-20043 third-party-advisory
- https://core.trac.wordpress.org/changeset/46893/trunk third-party-advisory
- https://github.com/WordPress/wordpress-develop/commit/1d1d5be7aa94608c04516cac4238e8c22b93c1d9 third-party-advisory
- https://wordpress.org/news/2019/12/wordpress-5-3-1-security-and-maintenance-release/ third-party-advisory
- https://wpvulndb.com/vulnerabilities/9973 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-20043 third-party-advisory