WordPress Core <= 3.5.1 - Denial of Service via wp-postpass cookie

2013-06-21 00:00
Anonymous

Strategic Overview

Status
Patched in 3.5.2
Affected CoreWordPress 3.5
Affected Version< 3.5.2
CVSS5.3Medium
CVECVE-2013-2173
View all WordPress 3.5 vulnerabilities

Vulnerability Overview

wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of service (CPU consumption) via a crafted value of a certain wp-postpass cookie.

Technical Analysis

REMEDIATION: Update to version 3.5.2, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C