CVE-2011-5270
21.01.2014, 01:55
wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.Enginsight
| Vendor | Product | Version |
|---|---|---|
| wordpress | wordpress | 𝑥 ≤ 3.0.5 |
| wordpress | wordpress | 3.0 |
| wordpress | wordpress | 3.0.1 |
| wordpress | wordpress | 3.0.2 |
| wordpress | wordpress | 3.0.3 |
| wordpress | wordpress | 3.0.4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration