SB2017011113 - Insufficient randomization in WordPress WordPress
Published: January 11, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Insufficient randomization (CVE-ID: CVE-2017-5493)
The vulnerability allows a remote attacker to bypass certain security restriction.
The vulnerability exists due to an error when choosing random numbers for keys within wp-includes/ms-functions.php script in the Multisite WordPress API. A remote attacker can create a specially crafted site signup or user signup request and bypass intended access restriction.
Successful exploitation of the vulnerability may allow an attacker to gain access to otherwise restricted functionality.
Remediation
Install update from vendor's website.