CVE-2012-5868

WordPress 3.4.2 - Session Fixation via Incomplete Logout Cookie Invalidation

Title source: llm
STIX 2.1

Description

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

Scores

EPSS 0.0065
EPSS Percentile 71.1%

Details

CWE
CWE-200
Status published
Products (1)
wordpress/wordpress 3.4.2
Published Dec 27, 2012
Tracked Since Feb 18, 2026