CVE-2010-5296

Source
https://cve.org/CVERecord?id=CVE-2010-5296
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2010-5296.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2010-5296
Downstream
Published
2014-01-21T01:55:03Z
Modified
2026-04-10T03:41:34.069824Z
Summary
[none]
Details

wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

References

Affected packages