Description In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API. Remediation References CVE-2017-9062 Related Vulnerabilities WordPress Plugin Church Admin Arbitrary File Upload (1.2530) WordPress Plugin Visualizer:Tables and Charts Manager for WordPress Multiple Vulnerabilities (3.3.0) Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0216) WordPress Plugin User Registration-Custom Registration Form, Login Form, and User Profile Privilege Escalation (3.2.0.1) Squid Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2013-0189) Severity High Classification CVE-2017-9062 CWE-707 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N Tags Missing Update Known Vulnerabilities