CVE-2012-4422
published 2012-09-14CVE-2012-4422: wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a…
PriorityP415low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.68%
74.3th percentile
wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.
Affected
90 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 3.4.2+dfsg-1 (bookworm) | wordpress 3.4.2+dfsg-1 (bookworm) |
| wordpress | wordpress | <= 3.4.1 | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv3.5LOW
vendor_debian3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2012-4422: wordpress - wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is en...
vendor_debian·2012·CVSS 3.5
CVE-2012-4422 [LOW] CVE-2012-4422: wordpress - wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is en...
wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.
Scope: local
bookworm: resolved (fixed in 3.4.2+dfsg-1)
bullseye: resolved (fixed in 3.4.2+dfsg-1)
forky: resolved (fixed in 3.4.2+dfsg-1)
sid: resolved (fixed in 3.4.2+dfsg-1)
trixie: resolved (fixed in 3.4.2+dfsg-1)
GHSA
GHSA-r8hm-p65m-rc9p: wp-admin/plugins
ghsa_unreviewed·2022-05-17
CVE-2012-4422 [LOW] GHSA-r8hm-p65m-rc9p: wp-admin/plugins
wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.
OSV
CVE-2012-4422: wp-admin/plugins
osv·2012-09-14·CVSS 3.5
CVE-2012-4422 [LOW] CVE-2012-4422: wp-admin/plugins
wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed plugin, which might allow remote authenticated users to make unintended plugin changes by leveraging the Administrator role.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://codex.wordpress.org/Version_3.4.2http://core.trac.wordpress.org/changeset?old_path=%2Ftags%2F3.4.1&old=21780&new_path=%2Ftags%2F3.4.2&new=21780#file42http://openwall.com/lists/oss-security/2012/09/13/4http://codex.wordpress.org/Version_3.4.2http://core.trac.wordpress.org/changeset?old_path=%2Ftags%2F3.4.1&old=21780&new_path=%2Ftags%2F3.4.2&new=21780#file42http://openwall.com/lists/oss-security/2012/09/13/4
2012-09-14
Published