CVE-2014-0165: WordPress

Medium severity, CVSS 4.0. EPSS: 2.4% chance of exploitation in the next 30 days.

WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-wp-posts-list-table.php.

Affected products

  • WordPress WordPress: up to and including 3.7.1; version 0.71 only; version 1.0 only; version 1.0.1 only; version 1.0.2 only; version 1.1.1 only; …

Published 2014-04-10. Last modified 2026-06-17.