WordPress Core < 5.4.1 - Password Reset Link Non-Expiration
Strategic Overview
- Status
- Patched in 3.7.33
- Affected Core
- WordPress 5.4
- Affected Version
3.7 – 5.4 · 19 branches- CVSS
- 6.1Medium
- Weakness type
- CWE-672 · Operation on a Resource after Expiration or Release
- CVE
CVE-2020-11027
At a glance
CVE-2020-11027 is a medium-severity Operation on a Resource after Expiration or Release vulnerability in the WordPress 5.4 WordPress release line, affecting 3.7 – 5.4 · 19 branches. It carries a CVSS score of 6.1 (reachable over the network; high confidentiality impact). Exploitation requires no authentication. The issue is fixed in version 3.7.33; sites on affected versions should update now. Disclosed April 2020, reported by Muaz Bin Abdus Sattar.
Vulnerability Overview
In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).
Technical Analysis
The vector marks this flaw as remotely reachable over the network, and no privileges on the target site. A successful exploit has high impact on confidentiality.
CWE-672: Operation on a Resource after Expiration or Release
The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.
Remediation
Update to one of the following versions, or a newer patched version: 3.7.33, 3.8.33, 3.9.31, 4.0.30, 4.1.30, 4.2.27, 4.3.23, 4.4.22, 4.5.21, 4.6.18, 4.7.17, 4.8.13, 4.9.14, 5.0.9, 5.1.5, 5.2.6, 5.3.3, 5.4.1
How does WordSec protect against this?
The fix is the thing that ends this: updating to 3.7.33 is the step that ends it.
- Alerts
External References
Related records
Other vulnerabilities in WordPress 5.4
- 9.8CVE-2026-63030: WordPress Core 6.9 - 7.0.1 Remote Code Execution
CVE-2026-63030 - 9.8CVE-2024-31211: WordPress Core 6.4.0 - 6.4.1 RCE POP Chain
CVE-2024-31211 - 9.8WordPress Core < 6.0.3 SQL Injection via WP_Date_Query
- 9.8CVE-2021-29476: WordPress Core < 5.5.3 PHP Object Injection Gadget
CVE-2021-29476 - 9.8CVE-2017-16510: WordPress Core SQL Injection
CVE-2017-16510 - 9.8CVE-2017-14723: WordPress Core < 4.8.2 SQL Injection
CVE-2017-14723 - 9.8CVE-2007-6013: WordPress Core 1.5 - 2.3.1 Authorization Bypass
CVE-2007-6013 - 9.8CVE-2007-6318: WordPress Core < 2.3.2 SQL Injection
CVE-2007-6318
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C