4
CVSSv2

CVE-2014-0165

Published: 10/04/2014 Updated: 16/12/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

WordPress prior to 3.7.2 and 3.8.x prior to 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress 3.7

wordpress wordpress

wordpress wordpress 3.4.2

wordpress wordpress 3.4.1

wordpress wordpress 3.2

wordpress wordpress 3.0.4

wordpress wordpress 3.0.3

wordpress wordpress 2.9

wordpress wordpress 3.8

wordpress wordpress 3.8.1

wordpress wordpress 3.4.0

wordpress wordpress 3.3.3

wordpress wordpress 3.1.4

wordpress wordpress 3.1.3

wordpress wordpress 3.0.2

wordpress wordpress 3.0.1

wordpress wordpress 2.8.5.2

wordpress wordpress 2.8.5.1

wordpress wordpress 3.6.1

wordpress wordpress 3.6

wordpress wordpress 3.3.2

wordpress wordpress 3.3.1

wordpress wordpress 3.1.2

wordpress wordpress 3.1.1

wordpress wordpress 3.1

wordpress wordpress 3.0

wordpress wordpress 2.9.2

wordpress wordpress 2.8.5

wordpress wordpress 2.8.4

wordpress wordpress 2.6.5

wordpress wordpress 2.6.3

wordpress wordpress 2.3.2

wordpress wordpress 2.3.1

wordpress wordpress 2.1.2

wordpress wordpress 2.1.1

wordpress wordpress 2.0.2

wordpress wordpress 2.0.11

wordpress wordpress 1.5.1.2

wordpress wordpress 1.5.1.1

wordpress wordpress 1.2.5

wordpress wordpress 1.2.4

wordpress wordpress 1.0

wordpress wordpress 0.71

wordpress wordpress 2.8.6

wordpress wordpress 2.8.2

wordpress wordpress 2.8.1

wordpress wordpress 2.6

wordpress wordpress 2.5.1

wordpress wordpress 2.2.2

wordpress wordpress 2.2.1

wordpress wordpress 2.0.8

wordpress wordpress 2.0.7

wordpress wordpress 2.0.6

wordpress wordpress 2.0

wordpress wordpress 1.6.2

wordpress wordpress 1.3.3

wordpress wordpress 1.3.2

wordpress wordpress 1.2.1

wordpress wordpress 1.2

wordpress wordpress 1.1.1

wordpress wordpress 2.8

wordpress wordpress 2.7.1

wordpress wordpress 2.7

wordpress wordpress 2.5

wordpress wordpress 2.3.3

wordpress wordpress 2.2

wordpress wordpress 2.1.3

wordpress wordpress 2.0.5

wordpress wordpress 2.0.4

wordpress wordpress 1.5.2

wordpress wordpress 1.5.1.3

wordpress wordpress 1.3

wordpress wordpress 1.0.2

wordpress wordpress 1.0.1

wordpress wordpress 3.5.1

wordpress wordpress 3.5.0

wordpress wordpress 3.3

wordpress wordpress 3.2.1

wordpress wordpress 3.0.6

wordpress wordpress 3.0.5

wordpress wordpress 2.9.1.1

wordpress wordpress 2.9.1

wordpress wordpress 2.8.3

wordpress wordpress 2.6.2

wordpress wordpress 2.6.1

wordpress wordpress 2.3

wordpress wordpress 2.2.3

wordpress wordpress 2.1

wordpress wordpress 2.0.9

wordpress wordpress 2.0.10

wordpress wordpress 2.0.1

wordpress wordpress 1.5.1

wordpress wordpress 1.5

wordpress wordpress 1.2.3

wordpress wordpress 1.2.2

Vendor Advisories

Debian Bug report logs - #744018 Wordpress 382 fixes two vulnerabilities [CVE-2014-0165 CVE-2014-0166] Package: wordpress; Maintainer for wordpress is Craig Small <csmall@debianorg>; Source for wordpress is src:wordpress (PTS, buildd, popcon) Reported by: Thijs Kinkhorst <thijs@debianorg> Date: Wed, 9 Apr 2014 0 ...
Debian Bug report logs - #744019 CVE-2014-0157: XSS in Horizon orchestration dashboard Package: src:horizon; Maintainer for src:horizon is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Thomas Goirand <zigo@debianorg> Date: Wed, 9 Apr 2014 09:21:01 UTC Severity: important Found in version hori ...