Insufficient randomization in WordPress WordPress



Published: 2017-01-11
Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2017-5493
CWE-ID CWE-330
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
WordPress
Web applications / CMS

Vendor WordPress.ORG

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Insufficient randomization

EUVDB-ID: #VU4862

Risk: Medium

CVSSv3.1: 6.4 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2017-5493

CWE-ID: CWE-330 - Use of Insufficiently Random Values

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass certain security restriction.

The vulnerability exists due to an error when choosing random numbers for keys within wp-includes/ms-functions.php script in the Multisite WordPress API. A remote attacker can create a specially crafted site signup or user signup request and bypass intended access restriction.

Successful exploitation of the vulnerability may allow an attacker to gain access to otherwise restricted functionality.

Mitigation

Update to version 4.7.1.

Vulnerable software versions

WordPress: 4.7

External links

http://wordpress.org/news/2017/01/wordpress-4-7-1-security-and-maintenance-release/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###