5
CVSSv2

CVE-2017-5493

Published: 15/01/2017 Updated: 03/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress prior to 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote malicious users to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

wordpress wordpress

Vendor Advisories

Debian Bug report logs - #852767 wordpress: 472 security release (CVE-2017-5610 CVE-2017-5611 CVE-2017-5612) Package: src:wordpress; Maintainer for src:wordpress is Craig Small <csmall@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 27 Jan 2017 06:18:01 UTC Severity: grave Tags: fixed- ...
An insufficient validation vulnerability has been discovered in wordpress leading to weak cryptographic security for multisite activation key ...