CVE-2012-4421: Medium severity wordpress vulnerability
The createpost function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4421?
The severity of CVE-2012-4421 is considered high due to its potential for privilege escalation.
How do I fix CVE-2012-4421?
To fix CVE-2012-4421, upgrade to WordPress version 3.4.2 or later.
What systems are affected by CVE-2012-4421?
CVE-2012-4421 affects WordPress versions prior to 3.4.2, as well as several earlier versions.
What types of attacks are associated with CVE-2012-4421?
CVE-2012-4421 can allow remote authenticated users to bypass access restrictions and publish posts.
Who is most at risk due to CVE-2012-4421?
Users with the Contributor role in WordPress installations prior to version 3.4.2 are most at risk.