VDB
CVE-2012-3383
CVE-2012-3383
PUBLISHED
CVSS 2.5999999046325684 LOW
The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leveraging the Administrator or Editor role and composing crafted text.
EPSS 0.15% · 35.9th percentile
Risk Scores
CVSS 2.0
2.5999999046325684
EPSS Score
0.15%
35.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| wordpress | wordpress | 3.4.0 |
Timeline
- Jul 22, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 17, 2022 CVE Updated
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- http://core.trac.wordpress.org/changeset?reponame=&new=21153%40branches%2F3.4&old=21076%40trunk#file16 url
- http://codex.wordpress.org/Version_3.4.2 url
- [oss-security] 20120707 Re: CVE #'s for WordPress 3.4.1 release mailing-list
- http://codex.wordpress.org/Version_3.4.1 url
- [oss-security] 20120912 Re: CVEs for wordpress 3.4.2 release mailing-list
- http://core.trac.wordpress.org/changeset?old_path=%2Ftags%2F3.4.1&old=21780&new_path=%2Ftags%2F3.4.2&new=21780#file23 url
- [oss-security] 20120702 CVE #'s for WordPress 3.4.1 release mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2012-3383 advisory