Description
Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.
Remediation
References
Related Vulnerabilities
e107 Other Vulnerability (CVE-2006-4757)
PHP Out-of-bounds Read Vulnerability (CVE-2025-14177)
WordPress Plugin Comment Rating SQL Injection and Security Bypass Weakness Vulnerabilities (2.9.32)
WordPress 4.6.x Multiple Vulnerabilities (4.6 - 4.6.25)
WordPress Plugin Child Theme Creator by Orbisius Cross-Site Request Forgery (1.5.1)