SB2017112935 - Insufficient randomization in WordPress WordPress 



SB2017112935 - Insufficient randomization in WordPress WordPress

Published: November 29, 2017

Security Bulletin ID SB2017112935
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Insufficient randomization (CVE-ID: CVE-2017-17091)

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists in wp-admin/user-new.php script due to usage of a determinate substring in newbloguser key, which can be directly derived from the user ID. A remote attacker can guess the key and bypass intended access restrictions.

Remediation

Install update from vendor's website.