PT-2012-5391 · WordPress · Wordpress
Published
2012-09-14
·
Updated
2012-09-17
·
CVE-2012-4421
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
WordPress versions prior to 3.4.2
Description
The issue concerns the create post function in WordPress, which fails to perform a capability check. This allows remote authenticated users with the Contributor role to bypass access restrictions and publish new posts using the Atom Publishing Protocol feature.
Recommendations
For versions prior to 3.4.2, update to version 3.4.2 or later to resolve the issue. As a temporary workaround, consider restricting the Contributor role's access to the Atom Publishing Protocol feature until the update is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordpress