VDB
CVE-2015-5623
CVE-2015-5623
PUBLISHED
CVSS 4 MEDIUM
WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.
EPSS 48.37% · 97.8th percentile
Risk Scores
CVSS 2.0
4
EPSS Score
48.37%
97.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| debian | debian_linux | 8.0 |
| wordpress | wordpress | 0 |
Timeline
- Aug 3, 2015 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 17, 2025 EPSS Score
- Mar 24, 2025 EPSS Score
- Mar 29, 2025 EPSS Score
- Mar 30, 2025 EPSS Score
- Apr 12, 2025 CVE Updated
- May 1, 2025 EPSS Score
- May 4, 2025 EPSS Score
- Jun 4, 2025 EPSS Score
- Jul 1, 2025 EPSS Score
References
- DSA-3328 vendor-advisory
- http://codex.wordpress.org/Version_4.2.3 url
- https://core.trac.wordpress.org/changeset/33357 url
- 1033037 vdb
- https://wordpress.org/news/2015/07/wordpress-4-2-3/ url
- 76011 vdb
- [oss-security] 20150723 Re: CVE request: WordPress 4.2.2 and earlier cross-site scripting vulnerability mailing-list
- https://wpvulndb.com/vulnerabilities/8111 url
- https://nvd.nist.gov/vuln/detail/CVE-2015-5623 advisory
- https://wordpress.org/news/2015/07/wordpress-4-2-3 url