Medium severity4.3NVD Advisory· Published Dec 27, 2019· Updated Jun 17, 2026
CVE-2019-20043
CVE-2019-20043
Description
In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contributor role does not have such rights, but this allowed them to bypass that. This has been patched in WordPress 5.3.1, along with all the previous WordPress versions from 3.7 to 5.3 via a minor release.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*range: >=3.7,<5.3.1
- (no CPE)range: 3.7 to 5.3.0
- WordPress/WordPressdescription
Patches
Vulnerability mechanics
References
8- core.trac.wordpress.org/changeset/46893/trunknvdPatch
- github.com/WordPress/wordpress-develop/commit/1d1d5be7aa94608c04516cac4238e8c22b93c1d9nvdThird Party Advisory
- github.com/WordPress/wordpress-develop/security/advisories/GHSA-g7rg-hchx-c2gwnvdThird Party Advisory
- seclists.org/bugtraq/2020/Jan/8nvdMailing ListThird Party Advisory
- wordpress.org/news/2019/12/wordpress-5-3-1-security-and-maintenance-release/nvdRelease NotesVendor Advisory
- wpvulndb.com/vulnerabilities/9973nvdRelease NotesThird Party Advisory
- www.debian.org/security/2020/dsa-4599nvdThird Party Advisory
- www.debian.org/security/2020/dsa-4677nvdThird Party Advisory
News mentions
0No linked articles in our index yet.