Input validation error in WordPress - CVE-2014-5203
Published: August 18, 2014 / Updated: August 10, 2020
Vulnerability identifier: #VU41397
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-5203
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.
Affected software
WordPress
Fedora
wordpress
Fedora
wordpress
How to mitigate CVE-2014-5203
Install update from vendor's website.
wordpress - addressed in versions 3.9.2-3.el5, 3.9.2-3.el6