Other nomination
WordPress Core RCE
Chained flaws in WordPress core let a read-only Subscriber edit posts: a missing post ID makes the capability check return an empty privilege array, a quick-draft handler hands out a valid CSRF token, and a 16MB list of taxonomy terms stalls one request long enough to win a race that makes the invented post ID real. CVE-2015-5623 and four related identifiers.
Record
- Researcher
- Netanel Rubin
- Published by
- Check Point Blog
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Netanel Rubin, first published at the original source. Preserved copies are kept so the citation survives its host.