CVE

Id
72500  
CVE No.
CVE-2014-5203  
Status
Candidate  
Description
wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.  
Phase
Assigned (20140813)  
Votes
None (candidate not yet proposed)  
Comments