Description
WordPress is prone to a security bypass vulnerability because the application fails to properly perform user-profile checks. Exploiting this issue could allow an attacker to perform otherwise restricted actions and subsequently publish posts under certain circumstances. Note that successful exploitation requires 'Contributor-level' privileges. WordPress versions prior to 3.1.2 are vulnerable.
Remediation
Update to WordPress version 3.0.6, 3.1.2 or latest
References
Related Vulnerabilities
Chamilo Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-13082)
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-1000356)
WordPress Plugin NextScripts:Social Networks Auto-Poster Cross-Site Scripting (4.2.7)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1734)