CVE-2017-5491
MEDIUMWordPress <4.7.1 - Auth Bypass
Title source: llmDescription
wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.
Scores
CVSS v3
5.3
EPSS
0.0162
EPSS Percentile
81.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Classification
CWE
CWE-1188
Status
published
Affected Products (2)
wordpress/wordpress
< 4.7
n/a/n/a
Timeline
Published
Jan 15, 2017
Tracked Since
Feb 18, 2026