WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.Referenceshttp://www.openwall.com/lists/oss-security/2012/07/08/1http://codex.wordpress.org/Version_3.4.1http://www.openwall.com/lists/oss-security/2012/07/02/1