CVE Vulnerabilities

CVE-2021-39203

Published: Sep 09, 2021 | Modified: Aug 05, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authenticated users who dont have permission to view private post types/data can bypass restrictions in the block editor under certain conditions. This affected WordPress 5.8 beta during the testing period. Its fixed in the final 5.8 release.

Affected Software

Name Vendor Start Version End Version
Wordpress Wordpress 5.8-beta1 (including) 5.8-beta1 (including)
Wordpress Ubuntu bionic *
Wordpress Ubuntu hirsute *
Wordpress Ubuntu impish *
Wordpress Ubuntu kinetic *
Wordpress Ubuntu lunar *
Wordpress Ubuntu mantic *
Wordpress Ubuntu trusty *
Wordpress Ubuntu xenial *

References