{"id":"BIT-wordpress-2021-39203","details":"WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions authenticated users who don't have permission to view private post types/data can bypass restrictions in the block editor under certain conditions. This affected WordPress 5.8 beta during the testing period. It's fixed in the final 5.8 release.","modified":"2026-03-13T04:57:14.025272020Z","published":"2024-01-31T15:28:46.965Z","withdrawn":"2026-03-13T04:47:02.180950Z","database_specific":{"cpes":["cpe:2.3:a:wordpress:wordpress:5.8:beta1:*:*:*:*:*:*"],"severity":"Medium"},"references":[{"type":"WEB","url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-qxvw-qxm9-qvg6"},{"type":"WEB","url":"https://hackerone.com/reports/1225282"}],"affected":[{"package":{"name":"wordpress","ecosystem":"Bitnami","purl":"pkg:bitnami/wordpress"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.8-beta1.0"},{"last_affected":"5.8-beta1.0"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/wordpress/BIT-wordpress-2021-39203.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}],"schema_version":"1.7.3"}