Access Control Flaw in Ghost Plugin for WordPress
CVE-2016-10983
6.5MEDIUM
What is CVE-2016-10983?
The Ghost plugin for WordPress, prior to version 0.5.6, is affected by an access control vulnerability that allows unauthorized users to export sensitive data through the endpoint /wp-admin/tools.php?ghostexport=true. This flaw poses significant risks as it may lead to the exposure of confidential information without proper authentication, highlighting the need for prompt updates and adherence to security best practices.