Description
WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended restrictions on publishing and authorship reassignment via unspecified vectors.
Remediation
References
Related Vulnerabilities
IBM RTC CVE-2020-4964 Vulnerability (CVE-2020-4964)
MySQL CVE-2012-0118 Vulnerability (CVE-2012-0118)
EspoCRM Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2025-32385)
WordPress 3.8.3 Multiple Vulnerabilities (3.8 - 3.8.3)
Oracle HTTP Server Uncontrolled Search Path Element Vulnerability (CVE-2019-5443)