CVE-2010-5297
EPSS 0.23%
Description
WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.
How to fix CVE-2010-5297
To remediate CVE-2010-5297, upgrade the affected package to a fixed version below.
- Debian/wordpress—upgrade to 3.0.1-1 or later
Is CVE-2010-5297 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.0.1-1