MGASA-2015-0290
Dashboard / Vulnerabilities / MGASA-2015-0290
Summary: Updated wordpress package fixes security vulnerabilities
Details: WordPress versions 4.2.2 and earlier are affected by a cross-site scripting vulnerability, which could allow users with the Contributor or Author role to compromise a site (CVE-2015-5622). WordPress versions 4.2.2 and earlier are affected by an issue where it was possible for a user with Subscriber permissions to create a draft through Quick Draft (CVE-2015-5623).
References: https://advisories.mageia.org/MGASA-2015-0290.html, https://bugs.mageia.org/show_bug.cgi?id=16457, http://codex.wordpress.org/Version_3.9.7, https://wordpress.org/news/2015/07/wordpress-4-2-3/, http://openwall.com/lists/oss-security/2015/07/23/18
Affected packages
Package
Name: wordpress
Purl: pkg:rpm/mageia/wordpress?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
