CVE-2013-4340

low
Published 2013-09-12 · Modified 2026-04-29
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-4340

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://wordpress.org/news/2013/09/wordpress-3-6-1/

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://core.trac.wordpress.org/changeset/25321

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://codex.wordpress.org/Version_3.6.1

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed3.6.1+dfsg-1
debian debianbullseyefixed3.6.1+dfsg-1
debian debianforkyfixed3.6.1+dfsg-1
debian debiansidfixed3.6.1+dfsg-1
debian debiantrixiefixed3.6.1+dfsg-1

Application impact

VendorProductVersionsFixed
wordpresswordpress{"endIncluding":"3.6"}

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.