From b578287c9e540c8ca4fba6a1064361b0f01c98a7 Mon Sep 17 00:00:00 2001 From: Ryan Dewhurst Date: Wed, 9 Apr 2014 13:56:50 -0700 Subject: [PATCH] Updated CVE 2014 0165 (markdown) --- CVE-2014-0165.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/CVE-2014-0165.md b/CVE-2014-0165.md index a2da78f..8a2761e 100644 --- a/CVE-2014-0165.md +++ b/CVE-2014-0165.md @@ -1,3 +1,7 @@ +From WordPress: + +"Privilege escalation: prevent contributors from publishing posts." + From the researcher (edik) who found the vulnerability: Using the bulk edit feature you can publish posts and pages PUBLICLY without the publishing-cap. The problem is that there are no checks for publishing-cap's on serverside. It's only protected in UI.