CVE-2017-5493
HIGHWordPress < 4.7 - Use of Cryptographically Weak PRNG in Multisite Signup Keys
Title source: llmDescription
wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.
References (8)
Core 8
Core References
Third Party Advisory x_refsource_misc
https://wpvulndb.com/vulnerabilities/8721
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/95401
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2017/dsa-3779
Release Notes, Vendor Advisory x_refsource_confirm
https://codex.wordpress.org/Version_4.7.1
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2017/01/14/6
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1037591
Patch x_refsource_confirm
https://github.com/WordPress/WordPress/commit/cea9e2dc62abf777e06b12ec4ad9d1aaa49b29f4
Vendor Advisory x_refsource_confirm
https://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/
Scores
CVSS v3
7.5
EPSS
0.0289
EPSS Percentile
85.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-338
Status
published
Products (1)
wordpress/wordpress
< 4.7
Published
Jan 15, 2017
Tracked Since
Feb 18, 2026