Description
wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.
Remediation
References
Related Vulnerabilities
WordPress Plugin Kama WP Smiles Unspecified Vulnerability (1.8.1)
WordPress Plugin Wbcom Designs-BuddyPress Group Reviews Security Bypass (2.8.3)
Lighttpd Other Vulnerability (CVE-2007-3947)
WebLogic CVE-2023-22108 Vulnerability (CVE-2023-22108)
WordPress Plugin NextScripts:Social Networks Auto-Poster Unspecified Vulnerability (4.3.2)