Weak Password Recovery Mechanism for Forgotten Password in WordPress - CVE-2020-11027

 

Weak Password Recovery Mechanism for Forgotten Password in WordPress - CVE-2020-11027

Published: April 29, 2020 / Updated: October 25, 2024


Vulnerability identifier: #VU27438
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11027
CWE-ID: CWE-640
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to compromise user accounts.

The vulnerability exists due to password reset token is not correctly invalidated. A remote attacker can abuse such behavior to take over another user account. 

Successful exploitation of the vulnerability may allows an attacker to gain full access to the affected website.


Affected software

WordPress
wordpress (Debian package)
wordpress
Fedora

How to mitigate CVE-2020-11027

Install updates from vendor's website.

WordPress - addressed in versions 3.7.33, 3.8.33, 3.9.31, 4.0.30, 4.1.30, 4.2.27, 4.3.23, 4.4.22, 4.5.21, 4.6.18, 4.7.17, 4.8.13, 4.9.14, 5.0.9, 5.1.5, 5.2.6, 5.3.3, 5.4.1
wordpress (Debian package) - addressed in versions 4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1
wordpress - addressed in versions 5.1.5-1.el6, 5.1.5-1.el7

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins