wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wordpress | Wordpress | * | 3.6 (including) |
Wordpress | Ubuntu | lucid | * |
Wordpress | Ubuntu | precise | * |
Wordpress | Ubuntu | quantal | * |
Wordpress | Ubuntu | raring | * |
Wordpress | Ubuntu | upstream | * |