ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2012-4421”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2012-4421
Published
2012-09-14
CVSS:
-
ShadowTrackr CVSS:
0.0
Summary:
The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.