VDB
DEBIAN-CVE-2009-2854
DEBIAN-CVE-2009-2854
PUBLISHED
Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7) export.php, (8) import.php, or (9) link-add.php in wp-admin/.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:13 | wordpress | 0, 0, 0 |
| Debian:14 | wordpress | 0 |
| Debian:11 | wordpress | 0, 0, 0 |
| Debian:12 | wordpress | 0, 0, 0 |
Timeline
- Aug 18, 2009 CVE Published
- May 7, 2026 CVE Updated