WordPress Vulnerabilities

WordPress 5.4 to 5.8 - Data Exposure via REST API

Description

On September 9, 2021 WordPress version 5.8.1 was released fixing three vulnerabilities.

The official blog post states:

"Props @mdawaffe, member of the WordPress Security Team for their work fixing a data exposure vulnerability within the REST API."

Affects WordPress

Fixed in WordPress 5.8.1
Fixed in WordPress 5.7.3
Fixed in WordPress 5.7.3
Fixed in WordPress 5.7.3
Fixed in WordPress 5.6.5
Fixed in WordPress 5.6.5
Fixed in WordPress 5.6.5
Fixed in WordPress 5.6.5
Fixed in WordPress 5.6.5
Fixed in WordPress 5.5.6
Fixed in WordPress 5.5.6
Fixed in WordPress 5.5.6
Fixed in WordPress 5.5.6
Fixed in WordPress 5.5.6
Fixed in WordPress 5.5.6
Fixed in WordPress 5.4.7
Fixed in WordPress 5.4.7
Fixed in WordPress 5.4.7
Fixed in WordPress 5.4.7
Fixed in WordPress 5.4.7
Fixed in WordPress 5.4.7
Fixed in WordPress 5.4.7

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
@mdawaffe
Verified
No

Timeline

Publicly Published
2021-09-09 (about 2 years ago)
Added
2021-09-09 (about 2 years ago)
Last Updated
2023-01-30 (about 1 years ago)

Other