{
  "modified": "2025-08-09T19:01:27Z",
  "published": "2010-02-23T20:30:00Z",
  "id": "CVE-2010-0682",
  "details": "WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.",
  "references": [
    {
      "type": "ADVISORY",
      "url": "http://secunia.com/advisories/38592"
    },
    {
      "type": "ADVISORY",
      "url": "http://secunia.com/advisories/42871"
    },
    {
      "type": "ADVISORY",
      "url": "http://wordpress.org/development/2010/02/wordpress-2-9-2/"
    },
    {
      "type": "FIX",
      "url": "http://wordpress.org/development/2010/02/wordpress-2-9-2/"
    },
    {
      "type": "WEB",
      "url": "http://hakre.wordpress.com/2010/02/16/the-short-memory-of-wordpress-org-security/"
    },
    {
      "type": "WEB",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052917.html"
    },
    {
      "type": "WEB",
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-January/052932.html"
    },
    {
      "type": "WEB",
      "url": "http://tmacuk.co.uk/?p=180"
    },
    {
      "type": "WEB",
      "url": "http://www.osvdb.org/62330"
    },
    {
      "type": "WEB",
      "url": "https://core.trac.wordpress.org/ticket/11236"
    }
  ]
}
