CVE-2014-0165: Medium severity WordPress vulnerability
WordPress 3.8.2 has been released and fixes the following issue:
"It also contains a fix to prevent a user with the Contributor role from improperly publishing posts. Reported by edik."
"Privilege escalation: prevent contributors from publishing posts. CVE-2014-0165."
References:
http://wordpress.org/news/2014/04/wordpress-3-8-2/ http://codex.wordpress.org/Version3.8.2
Other sources
WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/wordpressto a version that resolves this vulnerability.Fixed in 3.8.2 - Upgrade
Upgrade
wordpressto a version that resolves this vulnerability.Fixed in 3.8.2Patch CVE-2014-0165
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0165?
CVE-2014-0165 is classified as a moderate severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2014-0165?
To fix CVE-2014-0165, you should update your WordPress installation to version 3.8.2 or later.
What versions of WordPress are affected by CVE-2014-0165?
CVE-2014-0165 affects WordPress versions prior to 3.8.2.
What type of vulnerability is CVE-2014-0165?
CVE-2014-0165 is a privilege escalation vulnerability that allows users with limited roles to perform unauthorized actions.
Who reported the vulnerability CVE-2014-0165?
CVE-2014-0165 was reported by an individual identified as edik.