VulnerabilityModified
CVE-2014-0165
WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.
MEDIUM 4.0EPSS 2.37%
Does this matter?
Lower severity and a low EPSS score (2.37%). Track it; it rarely justifies an emergency change on its own.
Description
WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
- EPSS
- 2.37% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- wordpress/wordpress
- Source
- secalert@redhat.com
References
- http://codex.wordpress.org/Version_3.7.2Vendor Advisory
- http://codex.wordpress.org/Version_3.8.2Vendor Advisory
- http://core.trac.wordpress.org/changeset/27976
- http://www.debian.org/security/2014/dsa-2901
- https://bugzilla.redhat.com/show_bug.cgi?id=1085866
- http://codex.wordpress.org/Version_3.7.2Vendor Advisory
- http://codex.wordpress.org/Version_3.8.2Vendor Advisory
- http://core.trac.wordpress.org/changeset/27976
- http://www.debian.org/security/2014/dsa-2901
- https://bugzilla.redhat.com/show_bug.cgi?id=1085866
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.