CVE-2014-5266: Debian Linux
Medium severity, CVSS 5.0. EPSS: 25.2% chance of exploitation in the next 30 days.
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.
Affected products
- Debian Debian Linux: version 7.0 only
- Drupal Drupal: version 6.0 only; version 6.1 only; version 6.2 only; version 6.3 only; version 6.4 only; version 6.5 only; …
- WordPress WordPress: up to and including 3.9.1; version 3.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 3.0.4 only; …
Published 2014-08-18. Last modified 2026-06-17.