SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-14990

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read…

MEDIUM 6.5EPSS 2.09%

Does this matter?

Lower severity and a low EPSS score (2.09%). Track it; it rarely justifies an emergency change on its own.

Description

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
2.09% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-312
Affected
wordpress/wordpress · debian/debian linux
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.