CVE-2014-5203
EPSS 6.9%Published: 8/18/2014Modified: 5/27/2026
Also known as:DEBIAN-CVE-2014-5203
Description
wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.
Affected packages (1)
- Debian/wordpressfrom 0, < 3.9.2+dfsg-1