Back to search
CVE-2012-3383
Published: Jul 22, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leveraging the Administrator or Editor role and composing crafted text.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://codex.wordpress.org/Version_3.4.2
x_refsource_CONFIRM
[oss-security] 20120707 Re: CVE #'s for WordPress 3.4.1 release
mailing-list
x_refsource_MLIST
http://codex.wordpress.org/Version_3.4.1
x_refsource_CONFIRM
[oss-security] 20120912 Re: CVEs for wordpress 3.4.2 release
mailing-list
x_refsource_MLIST
[oss-security] 20120702 CVE #'s for WordPress 3.4.1 release
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now