WordPress Core < 3.4.2 - Missing Authorization Checks

2012-09-06 00:00
Anonymous

Strategic Overview

Status
Patched in 3.4.2
Affected CoreWordPress 3.4
Affected Version<= 3.4.1
CVSS3.8Low
CVECVE-2012-4422
View all WordPress 3.4 vulnerabilities

Vulnerability Overview

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.

Technical Analysis

REMEDIATION: Update to version 3.4.2, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C