Repository navigation
Comments, including notes, can be reparented by any authenticated user
Software
WordPress
Affected versions
7.1.0 - 7.1
7.0.0 - 7.0.4
6.9.0 - 6.9.7
6.8.0 - 6.8.8
6.7.0 - 6.7.7
6.6.0 - 6.6.7
6.5.0 - 6.5.10
6.4.0 - 6.4.10
6.3.0 - 6.3.10
6.2.0 - 6.2.11
6.1.0 - 6.1.12
6.0.0 - 6.0.14
5.9.0 - 5.9.16
5.8.0 - 5.8.15
5.7.0 - 5.7.17
5.6.0 - 5.6.19
5.5.0 - 5.5.20
5.4.0 - 5.4.21
5.3.0 - 5.3.23
Patched versions
7.1.1
7.0.5
6.9.8
6.8.9
6.7.8
6.6.8
6.5.11
6.4.11
6.3.11
6.2.12
6.1.13
6.0.15
5.9.17
5.8.16
5.7.18
5.6.20
5.5.21
5.4.22
5.3.24
An authenticated user (Author role suffices) who created a comment on their own post can send a request that reparents it onto a post they cannot edit.
WordPress 7.1.1 has been released containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 5.3.
Discovered and responsibly disclosed by Justin Hart, Viridis Security.