WordPress revision record leakage Vulnerability (CVE-2016-5835)
WordPress revision record leakage Vulnerability (CVE-2016-5835)
Release date:
Updated on:
Affected Systems:
WordPress <= 4.5.2
Description:
CVE (CAN) ID: CVE-2016-5835
WordPress is a blog platform developed in PHP.
A security vulnerability exists in versions earlier than WordPress 4.5.3. Remote attackers can exploit this vulnerability to read posts on the wp-admin/shortdes/ajax-actions.php and wp-admin/revision. php pages to obtain revision history.
<* Source: John Blackbourn
Dan Moen
*>
Suggestion:
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://codex.wordpress.org/Version_4.5.3
Https://wordpress.org/news/2016/06/wordpress-4-5-3/
This article permanently updates the link address: