Skip to content

WordPress 5.8 beta: Private data disclosure/privilege escalation through the block editor

Moderate
ehti published GHSA-qxvw-qxm9-qvg6 Sep 9, 2021

Package

No package listed

Affected versions

5.8 beta 1

Patched versions

5.8

Description

Impact

Authenticated users who don't have permission to view private post types/data can bypass restrictions in the block editor under certain conditions.

Patches

This affected WordPress 5.8 beta during the testing period. It's fixed in the final 5.8 release.

References

https://wordpress.org/news/category/releases/
https://hackerone.com/reports/1225282

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2021-39203

Weaknesses

No CWEs