CVE-2014-6412

WordPress Core < 4.4 - Brute Force Password Recovery Tokens

2015-02-12 00:00
Anonymous

Strategic Overview

Status
Patched in 4.4
Affected Core
WordPress 4.4
Affected Version
< 4.4
CVSS
7.5High
Weakness type
CWE-261 · Weak Encoding for Password
CVE
CVE-2014-6412
View all WordPress 4.4 vulnerabilities

At a glance

CVE-2014-6412 is a high-severity Weak Encoding for Password vulnerability in the WordPress 4.4 WordPress release line, affecting < 4.4. It carries a CVSS score of 7.5 (reachable over the network; low attack complexity; high confidentiality impact). Exploitation requires no authentication. The issue is fixed in version 4.4; sites on affected versions should update now. Disclosed February 2015.

Vulnerability Overview

WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

Technical Analysis

The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user. A successful exploit has high impact on confidentiality.

CWE-261: Weak Encoding for Password

Obscuring a password with a trivial encoding does not protect the password.

Remediation

Update to version 4.4, or a newer patched version

How does WordSec protect against this?

The fix is the thing that ends this: updating to 4.4 is the step that ends it.

  • Alerts

External References

Related records

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C