Add additional vulnerability for wordpress 4.7.1 that was initially kept

quiet by the wordpress team [1].

[1] https://make.wordpress.org/core/2017/02/01/disclosure-of-additional-security-fix-in-wordpress-4-7-2/

Security:	https://vuxml.FreeBSD.org/freebsd/54e50cd9-c1a8-11e6-ae1b-002590263bf5.html
This commit is contained in:
Ben Woods 2017-02-02 22:48:50 +00:00
parent e870fdb408
commit 509007bbe9
Notes: svn2git 2021-03-31 03:12:20 +00:00
svn path=/head/; revision=433182

View file

@ -204,6 +204,8 @@ Notes:
themes from accidentally causing a vulnerability.</li>
<li>A cross-site scripting (XSS) vulnerability was discovered in the
posts list table.</li>
<li>An unauthenticated privilege escalation vulnerability was
discovered in a REST API endpoint.</li>
</ul>
</blockquote>
</body>
@ -214,6 +216,7 @@ Notes:
<cvename>CVE-2017-5612</cvename>
<url>http://www.openwall.com/lists/oss-security/2017/01/28/5</url>
<url>https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release/</url>
<url>https://make.wordpress.org/core/2017/02/01/disclosure-of-additional-security-fix-in-wordpress-4-7-2/</url>
</references>
<dates>
<discovery>2017-01-26</discovery>