CVE-2012-4422

WordPress < 3.4.2 - Authenticated Unintended Plugin Activation via Multisite Feature

Title source: llm
STIX 2.1

Description

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.

References (3)

Core 3

Scores

EPSS 0.0024
EPSS Percentile 47.3%

Details

CWE
CWE-264
Status published
Products (49)
wordpress/wordpress 0.71
wordpress/wordpress 1.0
wordpress/wordpress 1.0.1
wordpress/wordpress 1.0.2
wordpress/wordpress 1.1.1
wordpress/wordpress 1.2
wordpress/wordpress 1.2.1
wordpress/wordpress 1.2.2
wordpress/wordpress 1.2.3
wordpress/wordpress 1.2.4
... and 39 more
Published Sep 14, 2012
Tracked Since Feb 18, 2026