Input validation error in WordPress - CVE-2014-5203

 

Input validation error in WordPress - CVE-2014-5203

Published: August 18, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41397
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-5203
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.


Affected software

WordPress
Fedora
wordpress

How to mitigate CVE-2014-5203

Install update from vendor's website.

wordpress - addressed in versions 3.9.2-3.el5, 3.9.2-3.el6

External References

Related Security Bulletins