Description
WordPress is prone to an unauthorized access vulnerability. Attackers can exploit this issue to edit other users' posts. Successfully exploiting this issue may lead to other attacks. WordPress versions prior to 2.3.3 are vulnerable.
Remediation
Update to WordPress version 2.3.3 or latest
References
http://www.village-idiot.org/archives/2008/02/02/wordpress-232-exploit-confirmed/
http://www.securiteam.com/unixfocus/5HP010KNFK.html
Related Vulnerabilities
WordPress Plugin WP e-Commerce-Store Toolkit Privilege Escalation (2.0.1)
Microsoft SQL Server Improper Input Validation Vulnerability (CVE-1999-0999)
MySQL CVE-2014-0401 Vulnerability (CVE-2014-0401)
WordPress Plugin Visualizer:Tables and Charts Manager for WordPress PHAR Deserialization (3.7.9)
Atlassian Confluence Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-3395)