CVE-2019-20043
Last modified
CVE-2019-20043 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. EPSS estimates a 2.48% chance of exploitation in the next 30 days.
Description
In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wordpress | Wordpress | >= 3.7, < 5.3.1 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
References
- https://seclists.org/bugtraq/2020/Jan/8Mailing List, Third Party Advisory
- https://wordpress.org/news/2019/12/wordpress-5-3-1-security-and-maintenance-release/Release Notes, Vendor Advisory
- https://wpvulndb.com/vulnerabilities/9973Release Notes, Third Party Advisory
- https://www.debian.org/security/2020/dsa-4599Third Party Advisory
- https://www.debian.org/security/2020/dsa-4677Third Party Advisory
- https://seclists.org/bugtraq/2020/Jan/8Mailing List, Third Party Advisory
- https://wordpress.org/news/2019/12/wordpress-5-3-1-security-and-maintenance-release/Release Notes, Vendor Advisory
- https://wpvulndb.com/vulnerabilities/9973Release Notes, Third Party Advisory
- https://www.debian.org/security/2020/dsa-4599Third Party Advisory
- https://www.debian.org/security/2020/dsa-4677Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-20043?
How severe is CVE-2019-20043?
How do I fix CVE-2019-20043?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-20031NEC UM8000, UM4730 and prior non-InMail voicemail systems wi…9.1
- CVE-2019-20032An attacker with access to an InMail voicemail box equipped …6.5
- CVE-2019-20033On Aspire-derived NEC PBXes, including all versions of SV810…9.8
- CVE-2019-2004In publishKeyEvent, publishMotionEvent and sendUnchainedFini…
- CVE-2019-20041wp_kses_bad_protocol in wp-includes/kses.php in WordPress be…9.8
- CVE-2019-20042In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the…6.1
- CVE-2019-20044In Zsh before 5.8, attackers able to execute commands can re…7.8
- CVE-2019-20045The Synergy Systems & Solutions PLC & RTU system has a vulne…7.5
- CVE-2019-20046The Synergy Systems & Solutions PLC & RTU system has a vulne…9.8
- CVE-2019-20047An issue was discovered on Alcatel-Lucent OmniVista 4760 dev…7.5
- CVE-2019-20048An issue was discovered on Alcatel-Lucent OmniVista 8770 dev…7.2
- CVE-2019-20049An issue was discovered on Alcatel-Lucent OmniVista 4760 dev…9.8
Are you affected by CVE-2019-20043?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
