CVE-2020-11027

WordPress Core < 5.4.1 - Password Reset Link Non-Expiration

2020-04-29 00:00
Muaz Bin Abdus Sattar

Strategic Overview

Status
Patched in 3.7.33
Affected Core
WordPress 5.4
Affected Version
3.7 – 5.4 · 19 branches
CVSS
6.1Medium
Weakness type
CWE-672 · Operation on a Resource after Expiration or Release
CVE
CVE-2020-11027
View all WordPress 5.4 vulnerabilities

At a glance

CVE-2020-11027 is a medium-severity Operation on a Resource after Expiration or Release vulnerability in the WordPress 5.4 WordPress release line, affecting 3.7 – 5.4 · 19 branches. It carries a CVSS score of 6.1 (reachable over the network; high confidentiality impact). Exploitation requires no authentication. The issue is fixed in version 3.7.33; sites on affected versions should update now. Disclosed April 2020, reported by Muaz Bin Abdus Sattar.

Vulnerability Overview

In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).

Technical Analysis

The vector marks this flaw as remotely reachable over the network, and no privileges on the target site. A successful exploit has high impact on confidentiality.

CWE-672: Operation on a Resource after Expiration or Release

The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.

Remediation

Update to one of the following versions, or a newer patched version: 3.7.33, 3.8.33, 3.9.31, 4.0.30, 4.1.30, 4.2.27, 4.3.23, 4.4.22, 4.5.21, 4.6.18, 4.7.17, 4.8.13, 4.9.14, 5.0.9, 5.1.5, 5.2.6, 5.3.3, 5.4.1

How does WordSec protect against this?

The fix is the thing that ends this: updating to 3.7.33 is the step that ends it.

  • Alerts

External References

Related records

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C