Lucene search

K
patchstackDawid GolunskiPATCHSTACK:15B8EC4221D09F3BD86571878FF519E7
HistoryMay 03, 2017 - 12:00 a.m.

WordPress <=4.7.4 - Host Header Injection in Password Reset

2017-05-0300:00:00
Dawid Golunski
patchstack.com
24

EPSS

0.026

Percentile

90.4%

The issue with the SERVER_NAME and PHP mail function allow an attacker to trick the WordPress send the password reset (crafted wp-login.php?action=lostpassword request) mail to the attackers SMTP server.

Solution

           Update WordPress to the latest possible version (at least 4.7.5)