Description
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.
Remediation
References
Related Vulnerabilities
WordPress 5.9.x Multiple Vulnerabilities (5.9 - 5.9.7)
WordPress Plugin Flog Cross-Site Scripting (0.1)
Jenkins Missing Authorization Vulnerability (CVE-2019-10354)
WordPress Plugin Theme Tweaker Cross-Site Request Forgery (5.20)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-0682)