Description
WordPress is prone to a security bypass vulnerability. Exploiting this issue could allow an attacker to perform otherwise restricted actions and subsequently read draft posts before they have been published. WordPress version 2.3.1 is vulnerable; prior versions may also be affected.
Remediation
Update to WordPress version 2.3.2 or latest
References
https://core.trac.wordpress.org/ticket/5487
http://www.securityfocus.com/archive/1/485160
Related Vulnerabilities
Joomla! Core 2.5.x Remote File Inclusion (2.5.4 - 2.5.25)
WordPress Plugin MapPress Maps for WordPress Cross-Site Request Forgery (2.53.8)
WordPress Plugin Live Search for WooCommerce Security Bypass (2.0.2)
Next.js Acceptance of Extraneous Untrusted Data With Trusted Data Vulnerability (CVE-2026-44572)