Description
The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.
Remediation
References
Related Vulnerabilities
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-5020)
Apache Tomcat Improper Resource Shutdown or Release Vulnerability (CVE-2022-25762)
MediaWiki Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2023-45369)
Jetty Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-26048)