CVE-2017-14990
MEDIUMWordPress 4.8.2 - Cleartext Storage of Sensitive Information in wp_signups.activation_key
Title source: llmDescription
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).
References (3)
Core 3
Core References
Third Party Advisory vendor-advisory
x_refsource_debian
https://www.debian.org/security/2017/dsa-3997
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1039554
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://core.trac.wordpress.org/ticket/38474
Scores
CVSS v3
6.5
EPSS
0.0038
EPSS Percentile
59.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-312
Status
published
Products (3)
debian/debian_linux
8.0
debian/debian_linux
9.0
wordpress/wordpress
4.8.2
Published
Oct 03, 2017
Tracked Since
Feb 18, 2026