Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-5493

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 81.1%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
References
Products affected by CVE-2017-5493


Contact Us

Shodan ® - All rights reserved