Skip to content

WordPress: Authenticated disclosure of password-protected posts and pages

Moderate
ehti published GHSA-pmmh-2f36-wvhq Apr 15, 2021

Package

No package listed

Affected versions

4.7 - 5.7

Patched versions

5.7.1

Description

Impact

One of the blocks in the WordPress editor can be exploited in a way that exposes password-protected posts and pages. This requires at least contributor privileges.

Patches

This has been patched in WordPress 5.7.1, along with the older affected versions via minor releases. It's strongly recommended that you keep auto-updates enabled to receive the fix.

References

https://wordpress.org/news/category/security/

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2021-29450

Weaknesses

No CWEs