Weak Password Recovery Mechanism for Forgotten Password in WordPress - CVE-2020-11027
Published: April 29, 2020 / Updated: October 25, 2024
Vulnerability details
The vulnerability allows a remote attacker to compromise user accounts.
The vulnerability exists due to password reset token is not correctly invalidated. A remote attacker can abuse such behavior to take over another user account.
Successful exploitation of the vulnerability may allows an attacker to gain full access to the affected website.
Affected software
wordpress (Debian package)
wordpress
Fedora
How to mitigate CVE-2020-11027
wordpress (Debian package) - addressed in versions 4.7.5+dfsg-2+deb9u6, 5.0.4+dfsg1-1+deb10u2, 5.4.1+dfsg1-1
wordpress - addressed in versions 5.1.5-1.el6, 5.1.5-1.el7
Links to Public Exploits and PoC-codes
External References
- https://wordpress.org/news/2020/04/wordpress-5-4-1/
- https://wpvulndb.com/vulnerabilities/10201/
- https://core.trac.wordpress.org/changeset/47634/
- https://www.wordfence.com/blog/2020/04/unpacking-the-7-vulnerabilities-fixed-in-todays-wordpress-5-4-1-security-update/
- https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ww7v-jg8c-q6jw