Lucene search

K
patchstackN/APATCHSTACK:35BD5EC987365670B27E50E0E79EBB2F
HistoryNov 29, 2017 - 12:00 a.m.

WordPress 3.7-4.9 - newbloguser Key Bypass

2017-11-2900:00:00
N/A
patchstack.com
59

EPSS

0.004

Percentile

72.8%

In wp-admin/user-new.php the newbloguser key is set to a string that can be get from the user ID, which allows an attacker to bypass intended access restrictions by entering this string.

Solution

           Update WordPress to 4.9.1

EPSS

0.004

Percentile

72.8%