CVE Vulnerabilities

CVE-2014-5203

Published: Aug 18, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.

Affected Software

NameVendorStart VersionEnd Version
WordpressWordpress3.9.0 (including)3.9.0 (including)
WordpressWordpress3.9.1 (including)3.9.1 (including)
WordpressUbuntulucid*
WordpressUbuntuprecise*
WordpressUbuntuupstream*

References