Security Risk: Severe Exploitation Level: Easy/Remote DREAD Score: 9/10 Vulnerability: Privilege Escalation / Content Injection. This vulnerability allows an unauthenticated user to modify the content of any post or page within a WordPress site. A fix for this was silently included on version 4.7.2 along with other less severe issues. This was done intentionally to give everyone time to patch. We are now disclosing the details because there has been enough time for most WordPress users to update their sites.”]
Source: https://blog.sucuri.net/2017/02/content-injection-vulnerability-wordpress-rest-api.html

