#VU4860 Spoofing attack in WordPress - CVE-2017-5491
Published: January 17, 2017 / Updated: January 17, 2017
WordPress
WordPress.ORG
Description
The vulnerability allows a remote attacker to bypass certain security restriction.
The vulnerability exists due to an error within wp-mail.php script. A remote attacker can bypass imposed posting restrictions using a spoofed mail server with name mail.example.com.
Successful exploitation of the vulnerability may allow an attacker to perform unauthorized postings.