Description
WordPress is prone to a security bypass vulnerability. Exploiting this issue could allow an attacker to perform otherwise restricted actions and subsequently read draft posts before they have been published. WordPress version 2.3.1 is vulnerable; prior versions may also be affected.
Remediation
Update to WordPress version 2.3.2 or latest
References
https://core.trac.wordpress.org/ticket/5487
http://www.securityfocus.com/archive/1/485160
Related Vulnerabilities
WordPress Plugin Inline Gallery 'do' Parameter Cross-Site Scripting (0.3.9)
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3730)
WordPress Plugin WordPress Photo Gallery by Gallery Bank Cross-Site Scripting (3.0.228)
MySQL CVE-2022-21489 Vulnerability (CVE-2022-21489)
WordPress Plugin Random image gallery with pretty photo zoom Cross-Site Scripting (7.4)