Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-11027

In affected versions of WordPress, a password reset link emailed to a user does not expire upon changing the user password. Access would be needed to the email account of the user by a malicious party for successful execution. This has been patched in version 5.4.1, along with all the previously affected versions via a minor release (5.3.3, 5.2.6, 5.1.5, 5.0.9, 4.9.14, 4.8.13, 4.7.17, 4.6.18, 4.5.21, 4.4.22, 4.3.23, 4.2.27, 4.1.30, 4.0.30, 3.9.31, 3.8.33, 3.7.33).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.391
EPSS Ranking 97.1%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 5.5
Products affected by CVE-2020-11027


Contact Us

Shodan ® - All rights reserved