WordPress Core <= 3.5.1 - Denial of Service via wp-postpass cookie
2013-06-21 00:00
AnonymousStrategic Overview
StatusPatched in 3.5.2
Affected CoreWordPress 3.5
Affected Version
< 3.5.2CVSS5.3Medium
CVE
CVE-2013-2173Vulnerability Overview
wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of service (CPU consumption) via a crafted value of a certain wp-postpass cookie.
Technical Analysis
REMEDIATION: Update to version 3.5.2, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C