Description
Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass. Sites that do not have the JSON:API module enabled are not affected.
Remediation
References
Related Vulnerabilities
WordPress Plugin Anti-Malware Security and Brute-Force Firewall Cross-Site Scripting (4.15.22)
PHP Address Book Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-2778)
Coppermine Cross-site Scripting (XSS) Vulnerability (CVE-2015-3921)
WordPress Plugin Easy Social Icons Cross-Site Scripting (3.0.8)