CVE-2011-0701
MEDIUM 4.0EPSS 3.2%
wp-admin/async-upload.php in the media uploader in WordPress before 3.0.5 allows remote authenticated users to read (1) draft posts or (2) private posts via a modified attachment_id parameter.
- CVSS v2.0
- 4.0 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N - EPSS
- 3.17% chance of exploitation in the next 30 days, 87th percentile
- Nuclei
- low
- Published
- 2011-03-14
- Updated
- 2024-08-06