Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ [REST API] Allow authors to read their own password protected posts

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š [REST API] Allow authors to read their own password protected posts


๐Ÿ’ก Newskategorie: Sicherheitslรผcken
๐Ÿ”— Quelle: portal.patchman.co

Allow authenticated users to read the contents of password protected posts if they have the `edit_post` meta capability for the post.

This vulnerability affects the following application versions:

  • WordPress 4.7
  • WordPress 4.7.1
  • WordPress 4.7.2
  • WordPress 4.7.3
  • WordPress 4.7.4
  • WordPress 4.7.5
  • WordPress 4.7.6
  • WordPress 4.7.7
  • WordPress 4.7.8
  • WordPress 4.7.9
  • WordPress 4.7.10
  • WordPress 4.7.11
  • WordPress 4.7.12
  • WordPress 4.7.13
  • WordPress 4.7.14
  • WordPress 4.7.15
  • WordPress 4.7.16
  • WordPress 4.7.17
  • WordPress 4.7.18
  • WordPress 4.7.19
  • WordPress 4.8
  • WordPress 4.8.1
  • WordPress 4.8.2
  • WordPress 4.8.3
  • WordPress 4.8.4
  • WordPress 4.8.5
  • WordPress 4.8.6
  • WordPress 4.8.7
  • WordPress 4.8.8
  • WordPress 4.8.9
  • WordPress 4.8.10
  • WordPress 4.8.11
  • WordPress 4.8.12
  • WordPress 4.8.13
  • WordPress 4.8.14
  • WordPress 4.8.15
  • WordPress 4.9
  • WordPress 4.9.1
  • WordPress 4.9.2
  • WordPress 4.9.3
  • WordPress 4.9.4
  • WordPress 4.9.5
  • WordPress 4.9.6
  • WordPress 4.9.7
  • WordPress 4.9.8
  • WordPress 4.9.9
  • WordPress 4.9.10
  • WordPress 4.9.11
  • WordPress 4.9.12
  • WordPress 4.9.13
  • WordPress 4.9.14
  • WordPress 4.9.15
  • WordPress 4.9.16
  • WordPress 5.0
  • WordPress 5.0.1
  • WordPress 5.0.2
  • WordPress 5.0.3
  • WordPress 5.0.4
  • WordPress 5.0.6
  • WordPress 5.0.7
  • WordPress 5.0.8
  • WordPress 5.0.9
  • WordPress 5.0.10
  • WordPress 5.0.11
  • WordPress 5.0 Beta 3
  • WordPress 5.0 Beta 4
  • WordPress 5.0 RC1
  • WordPress 5.0 RC2
  • WordPress 5.0 RC3
  • WordPress 5.1
  • WordPress 5.1.1
  • WordPress 5.1.2
  • WordPress 5.1.3
  • WordPress 5.1.4
  • WordPress 5.1.5
  • WordPress 5.1.6
  • WordPress 5.1.7
  • WordPress 5.1.8
  • WordPress 5.2
  • WordPress 5.2.1
  • WordPress 5.2.2
  • WordPress 5.2.3
  • WordPress 5.2.4
  • WordPress 5.2.5
  • WordPress 5.2.6
  • WordPress 5.2.7
  • WordPress 5.2.8
  • WordPress 5.2.9
  • WordPress 5.2 Beta 1
  • WordPress 5.2 Beta 2
  • WordPress 5.3
  • WordPress 5.3.1
  • WordPress 5.3.2
  • WordPress 5.3.3
  • WordPress 5.3.4
  • WordPress 5.3.5
  • WordPress 5.3.6
  • WordPress 5.4
  • WordPress 5.4.1
  • WordPress 5.4.2
  • WordPress 5.4.3
  • WordPress 5.4.4
  • WordPress 5.5
  • WordPress 5.5.1
  • WordPress 5.5.2
  • WordPress 5.5.3
  • WordPress 5.6
  • WordPress 5.6.1
  • WordPress 5.6.2
  • WordPress 5.7
...



๐Ÿ“Œ [REST API] Allow authors to read their own password protected posts


๐Ÿ“ˆ 99.27 Punkte

๐Ÿ“Œ Huawei releases it's own desktop PC with their own OS based on Linux and their own ARM CPU.


๐Ÿ“ˆ 41.23 Punkte

๐Ÿ“Œ CVE-2024-1088 | Password Protected Store for WooCommerce Plugin up to 1.9 on WordPress REST API information disclosure


๐Ÿ“ˆ 35.27 Punkte

๐Ÿ“Œ wp-google-maps Plugin up to 7.11.17 on WordPress REST API class.rest-api.php SELECT Statement sql injection


๐Ÿ“ˆ 33.74 Punkte

๐Ÿ“Œ WP Live Chat Support up to 8.0.32 on WordPress REST API REST API Call privilege escalation


๐Ÿ“ˆ 33.74 Punkte

๐Ÿ“Œ CVE-2023-39921 | Molongui Author Box, Guest Author and Co-Authors for Your Posts Plugin cross site scripting


๐Ÿ“ˆ 29.52 Punkte

๐Ÿ“Œ Some great first posts from new authors ๐Ÿ’ž


๐Ÿ“ˆ 29.52 Punkte

๐Ÿ“Œ Some great new posts from new authors in February ๐Ÿ’ž


๐Ÿ“ˆ 29.52 Punkte

๐Ÿ“Œ Some great new posts from new authors in March ๐Ÿ’ž


๐Ÿ“ˆ 29.52 Punkte

๐Ÿ“Œ Oracle Communications Session Route Manager 8.1.1/8.2.0/8.2.1 REST API insufficiently protected credentials


๐Ÿ“ˆ 29.25 Punkte

๐Ÿ“Œ Oracle Communications Session Report Manager 8.1.1/8.2.0/8.2.1 REST API insufficiently protected credentials


๐Ÿ“ˆ 29.25 Punkte

๐Ÿ“Œ Oracle Communications Element Manager 8.1.1/8.2.0/8.2.1 REST API insufficiently protected credentials


๐Ÿ“ˆ 29.25 Punkte

๐Ÿ“Œ Malware Authors Adopting the Freemium Model Spells Bad News for the Rest of Us


๐Ÿ“ˆ 28.63 Punkte

๐Ÿ“Œ Malware Authors Adopting the Freemium Model Spells Bad News for the Rest of Us


๐Ÿ“ˆ 28.63 Punkte

๐Ÿ“Œ [20170112] Public posts disclose user information through the REST API


๐Ÿ“ˆ 28.38 Punkte

๐Ÿ“Œ Silver Peak EdgeConnect SD-WAN up to 8.1.6.x REST API rest/json/banners JSON Data Trace information disclosure


๐Ÿ“ˆ 27.49 Punkte

๐Ÿ“Œ The REST API Handbook โ€“ How to Build, Test, Consume and Document REST APIs


๐Ÿ“ˆ 27.49 Punkte

๐Ÿ“Œ WordPress bis 4.7.0 REST API class-wp-rest-users-controller.php Information Disclosure


๐Ÿ“ˆ 27.49 Punkte

๐Ÿ“Œ WordPress bis 4.7.0 REST API class-wp-rest-users-controller.php Information Disclosure


๐Ÿ“ˆ 27.49 Punkte

๐Ÿ“Œ WordPress 4.7.0 REST API class-wp-rest-users-controller.php information disclosure


๐Ÿ“ˆ 27.49 Punkte

๐Ÿ“Œ Allow shop managers to only manipulate customers through REST API


๐Ÿ“ˆ 27.32 Punkte

๐Ÿ“Œ Check for permissions before allow edit REST API keys


๐Ÿ“ˆ 27.32 Punkte

๐Ÿ“Œ Metadata Analysis Draws its Own Conclusions on WannaCry Authors


๐Ÿ“ˆ 26.88 Punkte

๐Ÿ“Œ Malware Authors Inadvertently Take Down Own Botnet


๐Ÿ“ˆ 26.88 Punkte

๐Ÿ“Œ Buggy Phishing Kits Allow Criminals to Cannibalize Their Own


๐Ÿ“ˆ 26.62 Punkte

๐Ÿ“Œ Microsoft to allow Xbox Cloud Gaming users to bring their own games later this year


๐Ÿ“ˆ 26.62 Punkte

๐Ÿ“Œ Microsoft Will Allow Windows 10 Users to Create Their Own Fonts


๐Ÿ“ˆ 26.62 Punkte

๐Ÿ“Œ Do hard drive shredding companies allow home consumers to watch their own hard drives get shredded?


๐Ÿ“ˆ 26.62 Punkte

๐Ÿ“Œ Deere Will Allow Farmers To Repair Their Own Equipment


๐Ÿ“ˆ 26.62 Punkte

๐Ÿ“Œ Researchers Find New Hack to Read Content Of Password Protected PDF Files


๐Ÿ“ˆ 26.26 Punkte

๐Ÿ“Œ Pastebin adds 'Burn After Read' and 'Password Protected Pastes' to the dismay of the infosec community


๐Ÿ“ˆ 26.26 Punkte

๐Ÿ“Œ Pastebin Introduce New Security Features: โ€œBurn After Readโ€ And Password Protected Pastes


๐Ÿ“ˆ 26.26 Punkte











matomo