Description
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.
Remediation
References
Related Vulnerabilities
MySQL CVE-2017-10286 Vulnerability (CVE-2017-10286)
WordPress Plugin YOP Poll Unspecified Vulnerability (5.7.7)
WordPress Plugin demon image annotation Cross-Site Request Forgery (4.7)
Artifactory CVE-2023-42661 Vulnerability (CVE-2023-42661)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-7570)