Repository navigation
Missing `read_post` check in `attachment_submitbox_metadata()` leaks a private parent-post title
Software
WordPress
Affected versions
7.1.0 - 7.1
7.0.0 - 7.0.4
6.9.0 - 6.9.7
6.8.0 - 6.8.8
6.7.0 - 6.7.7
6.6.0 - 6.6.7
6.5.0 - 6.5.10
6.4.0 - 6.4.10
6.3.0 - 6.3.10
6.2.0 - 6.2.11
6.1.0 - 6.1.12
6.0.0 - 6.0.14
5.9.0 - 5.9.16
5.8.0 - 5.8.15
5.7.0 - 5.7.17
5.6.0 - 5.6.19
Patched versions
7.1.1
7.0.5
6.9.8
6.8.9
6.7.8
6.6.8
6.5.11
6.4.11
6.3.11
6.2.12
6.1.13
6.0.15
5.9.17
5.8.16
5.7.18
5.6.20
The attachment edit screen renders the parent post's title without a
read_postcheck, so alow-privilege Author can be shown the title of a private or draft parent post that they cannot otherwise read.
WordPress 7.1.1 has been released containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 5.6.
Discovered and responsibly disclosed by HDWSec.