wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://core.trac.wordpress.org/changeset/17710 | patch exploit |
http://codex.wordpress.org/Version_3.0.6 | vendor advisory |