ZeroHour

CVE-2017-17091

CVSS 3.0
8.8 high
EPSS
7%p94
Published
()
Modified
Description

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

Vendors
wordpress
Products
wordpress
Ecosystems
WordPress
Weakness
CWE-330
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.