WordPress Core < 3.5.2 - Missing Authorization Checks
2013-06-21 00:00
Konstantin KovsheninStrategic Overview
StatusPatched in 3.5.2
Affected CoreWordPress 3.5
Affected Version
<= 3.5.1CVSS6.3Medium
CVE
CVE-2013-2200Vulnerability Overview
WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended restrictions on publishing and authorship reassignment via unspecified vectors.
Technical Analysis
REMEDIATION: Update to version 3.5.2, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C