Lucene search

K
nessusTenable9099.PRM
HistoryFeb 26, 2016 - 12:00 a.m.

WordPress < 3.4.2 Multiple Vulnerabilities

2016-02-2600:00:00
Tenable
www.tenable.com
11

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

EPSS

0.002

Percentile

56.0%

Versions of WordPress prior to 3.4.2 are susceptible to the following vulnerabilities :

  • A flaw exists that is triggered when the ‘create_post’ function in the ‘wp-includes/class-wp-atom-server.php’ script fails to properly check for compatibility when creating new posts. This may allow a remote attacker to create a new post via the AtomPub feature. (CVE-2012-4421)
  • A flaw exists that is triggered when the ‘wp-admin/plugins.php’ scripts fails to enforce network-administrator privileges before activating a plugin across a network. This may allow a remote authenticated attacker to make unintended changes to a plugin. (CVE-2012-4422)
Binary data 9099.prm

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

EPSS

0.002

Percentile

56.0%