CVE

CVE-2019-20043

CVE-2019-20043

WordPress before 5.3.1 allowed an unauthenticated user to make a post sticky through the REST API because of missing access control in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php.

Source: CVE-2019-20043

Exit mobile version