Collected research
WordPress Core RCE
Finding Vulnerabilities in Core WordPress: A Bug Hunter's Trilogy, Part I
Chained flaws in WordPress core let a read-only Subscriber edit posts: a missing post ID makes the capability check return an empty privilege array, a quick-draft handler hands out a valid CSRF token, and a 16MB list of taxonomy terms stalls one request long enough to win a race that makes the invented post ID real. CVE-2015-5623 and four related identifiers.
Record
- Document
- Finding Vulnerabilities in Core WordPress: A Bug Hunter's Trilogy, Part I
- Researcher
- Netanel Rubin
- Published by
- Check Point Blog
- Date
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Netanel Rubin, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .