Description
WordPress is prone to a security bypass vulnerability because the application fails to properly perform user-profile checks. Exploiting this issue could allow an attacker to perform otherwise restricted actions and subsequently publish posts under certain circumstances. Note that successful exploitation requires 'Contributor-level' privileges. WordPress versions prior to 3.1.2 are vulnerable.
Remediation
Update to WordPress version 3.0.6, 3.1.2 or latest
References
Related Vulnerabilities
WordPress Plugin Dynamic Content for Elementor Remote Code Execution (1.9.5.6)
WordPress Plugin MapPress Maps for WordPress Cross-Site Request Forgery (2.53.8)
Joomla! Core 1.5.x Spam (1.5.0 - 1.5.6)
WordPress Plugin Article Directory Redux Cross-Site Scripting (1.0.2)
WordPress Plugin Easy PayPal Events Cross-Site Scripting (1.1.1)