Changes between Initial Version and Version 1 of Ticket #50497
- Timestamp:
- 06/28/2020 05:52:57 PM (5 years ago)
Legend:
- Unmodified
- Added
- Removed
- Modified
-
Ticket #50497
-
Property
Status
changed from
new
toclosed
-
Property
Component
changed from
Posts, Post Types
toWordPress.org Site
-
Property
Milestone
changed from
Awaiting Review
to - Property Keywords needs-testing has-patch removed
-
Property
Resolution
changed from
to
reported-upstream
-
Property
Severity
changed from
major
tonormal
-
Property
Status
changed from
-
Ticket #50497 – Description
initial v1 1 1 Steps To Reproduce: 2 2 3 In WordPress site https://wordpress.org, there are a lot themes uploaded by each vendor. And there is a rating and review form in each theme. In this phrase, the attacker can give review without stars rating although Word press enforces to give at least one star.3 In WordPress site https://wordpress.org, there are a lot themes uploaded by each vendor. And there is a rating and review form in each theme. In this phrase, the attacker can give review without stars rating although WordPress enforces to give at least one star. 4 4 5 5 When the reviewed form is submitted with any stars, the attacker will intercept the request and can delete rating parameter &rating=5&rating=5.