CVE-2012-4422: Low severity wordpress vulnerability
wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4422?
CVE-2012-4422 is classified as a medium severity vulnerability due to its potential exploitation by authenticated users.
How can I fix CVE-2012-4422?
The recommended fix for CVE-2012-4422 is to upgrade to WordPress version 3.4.2 or later.
Who is affected by CVE-2012-4422?
CVE-2012-4422 affects WordPress versions prior to 3.4.2 when the multisite feature is enabled.
What does CVE-2012-4422 allow attackers to do?
CVE-2012-4422 allows remote authenticated users to activate plugins without network-administrator privileges.
Is CVE-2012-4422 a remote or local vulnerability?
CVE-2012-4422 is considered a local vulnerability since it requires authentication to exploit.