CVE-2012-2402: Medium severity wordpress vulnerability
wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2402?
CVE-2012-2402 has a medium severity rating due to the potential for unauthorized deactivation of network-wide plugins by authenticated administrators.
How do I fix CVE-2012-2402?
To fix CVE-2012-2402, upgrade to WordPress version 3.3.2 or later, which addresses this vulnerability.
Which versions of WordPress are affected by CVE-2012-2402?
CVE-2012-2402 affects all WordPress versions before 3.3.2, specifically those prior to version 3.3.1.
What type of vulnerability is CVE-2012-2402?
CVE-2012-2402 is a privilege escalation vulnerability that allows remote authenticated administrators to bypass access restrictions.
How does CVE-2012-2402 impact WordPress site security?
CVE-2012-2402 can compromise the security of a WordPress site by allowing unauthorized functionality, such as deactivating critical plugins on a network.