WordPress Core < 4.4 - Brute Force Password Recovery Tokens

2015-02-12 00:00
Anonymous

Strategic Overview

Status
Patched in 4.4
Affected CoreWordPress 4.4
Affected Version< 4.4
CVSS7.5High
CVECVE-2014-6412
View all WordPress 4.4 vulnerabilities

Vulnerability Overview

WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

Technical Analysis

REMEDIATION: Update to version 4.4, or a newer patched version --- IDENTIFIER: CWE-261 (Weak Encoding for Password) Obscuring a password with a trivial encoding does not protect the password.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C