Description
xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote
authenticated users with the contributor role to bypass intended access
restrictions and invoke the publish_posts functionality, which can be used
to "publish a previously saved post."