Description
wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.
Remediation
References
Related Vulnerabilities
WordPress Plugin Chameleon CSS SQL Injection (1.2)
WordPress Plugin Pym.js Embeds Cross-Site Scripting (1.3.2)
Grafana Improper Authentication Vulnerability (CVE-2021-28148)
WordPress Plugin WP Songbook Cross-Site Scripting (2.0.11)
WordPress Plugin Font-official webfonts plugin of Fonts For Web Cross-Site Scripting (7.5.1)