CVE-2012-2402
published 2012-04-21CVE-2012-2402: wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate…
PriorityP427medium5.5CVSS 2.0
AVNACLAuSCNIPAP
EPSS
2.61%
83.7th percentile
wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspecified vectors.
Affected
83 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 3.3.2+dfsg-1 (bookworm) | wordpress 3.3.2+dfsg-1 (bookworm) |
| wordpress | wordpress | <= 3.3.1 | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4qcm-5888-4f65: wp-admin/plugins
ghsa_unreviewed·2022-05-17
CVE-2012-2402 [MEDIUM] GHSA-4qcm-5888-4f65: wp-admin/plugins
wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspecified vectors.
OSV
CVE-2012-2402: wp-admin/plugins
osv·2012-04-21·CVSS 5.5
CVE-2012-2402 [MEDIUM] CVE-2012-2402: wp-admin/plugins
wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspecified vectors.
Debian
CVE-2012-2402: wordpress - wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site ...
vendor_debian·2012·CVSS 5.5
CVE-2012-2402 [MEDIUM] CVE-2012-2402: wordpress - wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site ...
wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 3.3.2+dfsg-1)
bullseye: resolved (fixed in 3.3.2+dfsg-1)
forky: resolved (fixed in 3.3.2+dfsg-1)
sid: resolved (fixed in 3.3.2+dfsg-1)
trixie: resolved (fixed in 3.3.2+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2402 wordpress (X < v3.3.2): Remote authenticated site administrators able to deactivate network-wide plugins under certain circumstances
bugzilla·2012-04-23·CVSS 5.5
CVE-2012-2402 [MEDIUM] CVE-2012-2402 wordpress (X < v3.3.2): Remote authenticated site administrators able to deactivate network-wide plugins under certain circumstances
CVE-2012-2402 wordpress (X < v3.3.2): Remote authenticated site administrators able to deactivate network-wide plugins under certain circumstances
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-2402 to the following vulnerability:
wp-admin/plugins.php in WordPress before 3.3.2 allows remote authenticated site administrators to bypass intended access restrictions and deactivate network-wide plugins via unspecified vectors.
References:
http://core.trac.wordpress.org/changeset/20526/branches/3.3/wp-admin/plugins.php
http://wordpress.org/news/2012/04/wordpress-3-3-2/
Discussion:
This issue affects the versions of the wordpress package, as shipped with Fedora release of 15 and 16.
--
This issue affects the versions of the wordpress package, as shipped with Fedora EP
Bugzilla
CVE-2012-2399 CVE-2012-2400 CVE-2012-2402 CVE-2012-2403 CVE-2012-2404 wordpress various flaws [epel-5]
bugzilla·2012-04-23·CVSS 10.0
CVE-2012-2399 [CRITICAL] CVE-2012-2399 CVE-2012-2400 CVE-2012-2402 CVE-2012-2403 CVE-2012-2404 wordpress various flaws [epel-5]
CVE-2012-2399 CVE-2012-2400 CVE-2012-2402 CVE-2012-2403 CVE-2012-2404 wordpress various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/
http://core.trac.wordpress.org/changeset/20526/branches/3.3/wp-admin/plugins.phphttp://osvdb.org/81462http://secunia.com/advisories/48957http://secunia.com/advisories/49138http://wordpress.org/news/2012/04/wordpress-3-3-2/http://www.debian.org/security/2012/dsa-2470http://www.securityfocus.com/bid/53192https://exchange.xforce.ibmcloud.com/vulnerabilities/75090https://exchange.xforce.ibmcloud.com/vulnerabilities/75207http://core.trac.wordpress.org/changeset/20526/branches/3.3/wp-admin/plugins.phphttp://osvdb.org/81462http://secunia.com/advisories/48957http://secunia.com/advisories/49138http://wordpress.org/news/2012/04/wordpress-3-3-2/http://www.debian.org/security/2012/dsa-2470http://www.securityfocus.com/bid/53192https://exchange.xforce.ibmcloud.com/vulnerabilities/75090https://exchange.xforce.ibmcloud.com/vulnerabilities/75207
2012-04-21
Published