{"id":"CVE-2011-5270","details":"wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.","modified":"2026-04-10T03:44:10.666653Z","published":"2014-01-21T01:55:03Z","references":[{"type":"ADVISORY","url":"http://codex.wordpress.org/Version_3.0.6"},{"type":"EVIDENCE","url":"https://core.trac.wordpress.org/changeset/17710"},{"type":"FIX","url":"https://core.trac.wordpress.org/changeset/17710"}],"schema_version":"1.7.5"}