CVE-2014-5203: WordPress
High severity, CVSS 7.5. EPSS: 3.9% chance of exploitation in the next 30 days.
wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.
Affected products
- WordPress WordPress: version 3.9.0 only; version 3.9.1 only
Published 2014-08-18. Last modified 2026-06-17.