CVE-2014-5203: WordPress

High severity, CVSS 7.5. EPSS: 3.9% chance of exploitation in the next 30 days.

wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.

Affected products

  • WordPress WordPress: version 3.9.0 only; version 3.9.1 only

Published 2014-08-18. Last modified 2026-06-17.