← Back

CVE-2017-1001000

nvd nist
Published: Apr 3, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identifier, which allows remote attackers to modify arbitrary pages via a request for wp-json/wp/v2/posts followed by a numeric value and a non-numeric value, as demonstrated by the wp-json/wp/v2/posts/123?id=123helloworld URI.

Affected (3)

Products: Wordpress: Wordpress
1 product
Wordpress
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Wordpress
Version 4.7.1
Version 4.7.2
Version 4.7

References (18)

Source: 46fe6300-5254-4a98-9594-a9567bec8179
Source: 46fe6300-5254-4a98-9594-a9567bec8179
Source: 46fe6300-5254-4a98-9594-a9567bec8179
Source: 46fe6300-5254-4a98-9594-a9567bec8179
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.