CVE

Id
47881  
CVE No.
CVE-2010-5297  
Status
Candidate  
Description
WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.  
Phase
Assigned (20140120)  
Votes
None (candidate not yet proposed)  
Comments