CVE-2012-4421
Publication date 14 September 2012
Last updated 24 July 2024
Ubuntu priority
The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.
Status
Package | Ubuntu Release | Status |
---|---|---|
wordpress | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |