CVE-2010-5296
4.9
Vector
AV:N/AC:M/Au:S/C:P/I:P/A:N
Exploitability: 6.8 / Impact: 4.9
Source: NVD
Description
wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.
Affected (48)
Related CWEs
References (4)
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch
Timeline
No history available yet.