CVE-2017-14990
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read…
Does this matter?
Lower severity and a low EPSS score (2.09%). Track it; it rarely justifies an emergency change on its own.
Description
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.09% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-312
- Affected
- wordpress/wordpress · debian/debian linux
- Source
- cve@mitre.org
References
- http://www.securitytracker.com/id/1039554Third Party Advisory, VDB Entry
- https://core.trac.wordpress.org/ticket/38474Exploit, Issue Tracking, Third Party Advisory
- https://www.debian.org/security/2017/dsa-3997Third Party Advisory
- http://www.securitytracker.com/id/1039554Third Party Advisory, VDB Entry
- https://core.trac.wordpress.org/ticket/38474Exploit, Issue Tracking, Third Party Advisory
- https://www.debian.org/security/2017/dsa-3997Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.