VYPR
Unrated severityNVD Advisory· Published Sep 14, 2012· Updated Jun 16, 2026

CVE-2012-4421

CVE-2012-4421

Description

The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contributor role and using the Atom Publishing Protocol (aka AtomPub) feature.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

88
  • WordPress/WordPress88 versions
    cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*+ 87 more
    • cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*range: <=3.4.1
    • cpe:2.3:a:wordpress:wordpress:0.71:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.2.5:a:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.5.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.5.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.5.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:1.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.10:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.11:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.7:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.8:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.0.9:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.6.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.6.5:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.7:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8.4:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8.4:a:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8.5:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.8.6:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.9:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.9.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.9.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:2.9.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:wordpress:wordpress:3.4.0:*:*:*:*:*:*:*
    • (no CPE)range: <3.4.2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.