Blog post

WordPress Privilege Escalation through Post Types

Simon Scannell photo

Simon Scannell

Vulnerability Researcher

A logic flaw in the way WordPress created blog posts allowed attackers to access features only administrators were supposed to have (CVE-2018-20152). This lead to a Stored XSS and Object ...