IsItPatchedInstant security status for any software version
← All products

CVE-2015-5623

MEDIUM severity · CVSS 4 · Improper access control
4CVSS MEDIUM

Summary

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.

Impact & exploitability

Attack vectorNetwork
Attack complexityLow
Privileges required
User interaction
Confidentiality impactNone
Integrity impact
Availability impactNone
Exploit probability (EPSS)48%

AV:N/AC:L/Au:S/C:N/I:P/A:N

Affected products we track (2)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: http://codex.wordpress.org/Version_4.2.3 ↗

Last checked: Wed, 10 Jun 2026 22:18:30 UTC