Web Hack List

Collected research

WordPress Core RCE

Finding Vulnerabilities in Core WordPress: A Bug Hunter's Trilogy, Part I

Chained flaws in WordPress core let a read-only Subscriber edit posts: a missing post ID makes the capability check return an empty privilege array, a quick-draft handler hands out a valid CSRF token, and a 16MB list of taxonomy terms stalls one request long enough to win a race that makes the invented post ID real. CVE-2015-5623 and four related identifiers.

Record

Document
Finding Vulnerabilities in Core WordPress: A Bug Hunter's Trilogy, Part I
Researcher
Netanel Rubin
Published by
Check Point Blog
Date
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Netanel Rubin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .