VulnerabilityModified
CVE-2014-0166
The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a…
MEDIUM 6.4EPSS 8.93%
Does this matter?
Lower severity and a low EPSS score (8.93%). Track it; it rarely justifies an emergency change on its own.
Description
The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 8.93% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- wordpress/wordpress
- Source
- secalert@redhat.com
References
- http://codex.wordpress.org/Version_3.7.2Vendor Advisory
- http://codex.wordpress.org/Version_3.8.2Vendor Advisory
- http://core.trac.wordpress.org/changeset/28054
- http://www.debian.org/security/2014/dsa-2901
- https://bugzilla.redhat.com/show_bug.cgi?id=1085858
- http://codex.wordpress.org/Version_3.7.2Vendor Advisory
- http://codex.wordpress.org/Version_3.8.2Vendor Advisory
- http://core.trac.wordpress.org/changeset/28054
- http://www.debian.org/security/2014/dsa-2901
- https://bugzilla.redhat.com/show_bug.cgi?id=1085858
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.