CVE-2012-4421
Last modified
CVE-2012-4421 is a vulnerability of currently unknown severity. The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.. EPSS estimates a 1.90% chance of exploitation in the next 30 days.
Description
The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wordpress | Wordpress | <= 3.4.1 |
| Wordpress | Wordpress | 0.71 |
| Wordpress | Wordpress | 1.0 |
| Wordpress | Wordpress | 1.0.1 |
| Wordpress | Wordpress | 1.0.2 |
| Wordpress | Wordpress | 1.1.1 |
| Wordpress | Wordpress | 1.2 |
| Wordpress | Wordpress | 1.2.1 |
| Wordpress | Wordpress | 1.2.2 |
| Wordpress | Wordpress | 1.2.3 |
| Wordpress | Wordpress | 1.2.4 |
| Wordpress | Wordpress | 1.2.5 |
| Wordpress | Wordpress | 1.3 |
| Wordpress | Wordpress | 1.3.2 |
| Wordpress | Wordpress | 1.3.3 |
| Wordpress | Wordpress | 1.5 |
| Wordpress | Wordpress | 1.5.1 |
| Wordpress | Wordpress | 1.5.1.1 |
| Wordpress | Wordpress | 1.5.1.2 |
| Wordpress | Wordpress | 1.5.1.3 |
| Wordpress | Wordpress | 1.5.2 |
| Wordpress | Wordpress | 2.0 |
| Wordpress | Wordpress | 2.0.1 |
| Wordpress | Wordpress | 2.0.2 |
| Wordpress | Wordpress | 2.0.4 |
| Wordpress | Wordpress | 2.0.5 |
| Wordpress | Wordpress | 2.0.6 |
| Wordpress | Wordpress | 2.0.7 |
| Wordpress | Wordpress | 2.0.8 |
| Wordpress | Wordpress | 2.0.9 |
| Wordpress | Wordpress | 2.0.10 |
| Wordpress | Wordpress | 2.0.11 |
| Wordpress | Wordpress | 2.1 |
| Wordpress | Wordpress | 2.1.1 |
| Wordpress | Wordpress | 2.1.2 |
| Wordpress | Wordpress | 2.1.3 |
| Wordpress | Wordpress | 2.2 |
| Wordpress | Wordpress | 2.2.1 |
| Wordpress | Wordpress | 2.2.2 |
| Wordpress | Wordpress | 2.2.3 |
| Wordpress | Wordpress | 2.3 |
| Wordpress | Wordpress | 2.3.1 |
| Wordpress | Wordpress | 2.3.2 |
| Wordpress | Wordpress | 2.3.3 |
| Wordpress | Wordpress | 2.5 |
| Wordpress | Wordpress | 2.5.1 |
| Wordpress | Wordpress | 2.6 |
| Wordpress | Wordpress | 2.6.1 |
| Wordpress | Wordpress | 2.6.2 |
| Wordpress | Wordpress | 2.6.3 |
Showing 50 of 85 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-4421?
How severe is CVE-2012-4421?
How do I fix CVE-2012-4421?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-4415Stack-based buffer overflow in the guac_client_plugin_open f…
- CVE-2012-4416Unspecified vulnerability in the Java Runtime Environment (J…
- CVE-2012-4417GlusterFS 3.3.0, as used in Red Hat Storage server 2.0, allo…
- CVE-2012-4418Apache Axis2 allows remote attackers to forge messages and b…
- CVE-2012-4419The compare_tor_addr_to_addr_policy function in or/policies.…
- CVE-2012-4420An information disclosure flaw was found in the way the Java…7.5
- CVE-2012-4422wp-admin/plugins.php in WordPress before 3.4.2, when the mul…
- CVE-2012-4423The virNetServerProgramDispatchCall function in libvirt befo…
- CVE-2012-4424Stack-based buffer overflow in string/strcoll_l.c in the GNU…
- CVE-2012-4425libgio, when used in setuid or other privileged programs in …
- CVE-2012-4426Multiple format string vulnerabilities in mcrypt 2.6.8 and e…
- CVE-2012-4427The gnome-shell plugin 3.4.1 in GNOME allows remote attacker…
Are you affected by CVE-2012-4421?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
