Description
wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft.
Remediation
References
Related Vulnerabilities
Liferay Portal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-26272)
Vanilla Forums Improper Input Validation Vulnerability (CVE-2011-0908)
LimeSurvey Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3752)
WordPress Plugin WP Private Content Plus Security Bypass (1.31)