Lucene search

K
cvelistRedhatCVELIST:CVE-2012-4421
HistorySep 14, 2012 - 7:00 p.m.

CVE-2012-4421

2012-09-1419:00:00
redhat
www.cve.org
4
wordpress
create_post function
access restrictions
contributor role
atompub

AI Score

6.1

Confidence

Low

EPSS

0.002

Percentile

56.0%

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

AI Score

6.1

Confidence

Low

EPSS

0.002

Percentile

56.0%