7.5
CVSSv3

CVE-2016-5838

Published: 29/06/2016 Updated: 30/11/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

WordPress prior to 4.5.3 allows remote malicious users to bypass intended password-change restrictions by leveraging knowledge of a cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress

Vendor Advisories

Several vulnerabilities were discovered in wordpress, a web blogging tool, which could allow remote attackers to compromise a site via cross-site scripting, bypass restrictions, obtain sensitive revision-history information, or mount a denial of service For the stable distribution (jessie), these problems have been fixed in version 41+dfsg-1+deb8 ...