Wordfence <= 5.2.3 - Multiple Protection Mechanism Bypasses

2014-09-14 00:00
Voxel@Night

Vulnerability Overview

The Wordfence Plugin is vulnerable to multiple protection mechanism bypasses in version up to, and including, 5.2.3. These allow unauthenticated attackers to bypass exploit protection and throttling restrictions.

Technical Analysis

REMEDIATION: Update to version 5.2.4, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C