Описание
WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.
Ссылки
- Third Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Issue TrackingThird Party Advisory
- Issue TrackingVendor Advisory
- Third Party AdvisoryVDB Entry
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Issue TrackingThird Party Advisory
- Issue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.4.0 (исключая)
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
EPSS
Процентиль: 88%
0.04417
Низкий
8.1 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-640
Связанные уязвимости
CVSS3: 8.1
ubuntu
около 7 лет назад
WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.
CVSS3: 8.1
debian
около 7 лет назад
WordPress before 4.4 makes it easier for remote attackers to predict p ...
CVSS3: 8.1
github
около 3 лет назад
WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.
EPSS
Процентиль: 88%
0.04417
Низкий
8.1 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-640