WordPress <= 5.0 - Authenticated Post Type Bypass



Description
According to WordPress:

"Simon Scannell of RIPS Technologies discovered that authors could create posts of unauthorized post types with specially crafted input."

Affects WordPresses

fixed in version 5.0.1
fixed in version 4.9.9
fixed in version 4.9.9
fixed in version 4.9.9
fixed in version 4.9.9
fixed in version 4.9.9
fixed in version 4.9.9
fixed in version 4.9.9
fixed in version 4.9.9
fixed in version 4.9.9
fixed in version 4.8.8
fixed in version 4.8.8
fixed in version 4.8.8
fixed in version 4.8.8
fixed in version 4.8.8
fixed in version 4.8.8
fixed in version 4.8.8
fixed in version 4.8.8
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.7.12
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.6.13
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.5.16
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.4.17
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.3.18
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.2.22
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.1.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 4.0.25
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.9.26
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.8.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28
fixed in version 3.7.28

References

CVE 2018-20152
URL https://wordpress.org/news/2018/12/wordpress-5-0-1-security-release/
URL https://blog.ripstech.com/2018/wordpress-post-type-privilege-escalation/

Classification

Type BYPASS

Miscellaneous

Original Researcher RIPS Technologies (Simon Scannell)
Submitter Ryan Dewhurst
Submitter Website https://dewhurstsecurity.com/
Submitter Twitter ethicalhack3r
Views 18548
Verified No
WPVDB ID 9170

Timeline

Publicly Published 2018-12-13 (7 months ago)
Added 2018-12-13 (7 months ago)
Last Updated 2019-01-10 (6 months ago)