PT-2014-3511 · WordPress · Wordpress

Published

2014-04-09

·

Updated

2017-12-16

·

CVE-2014-0166

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions WordPress versions prior to 3.7.2 WordPress versions 3.8.x prior to 3.8.2
Description The issue concerns the wp validate auth cookie function in wp-includes/pluggable.php, which does not properly determine the validity of authentication cookies. This makes it easier for remote attackers to obtain access via a forged cookie.
Recommendations For WordPress versions prior to 3.7.2, update to version 3.7.2 or later. For WordPress versions 3.8.x prior to 3.8.2, update to version 3.8.2 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-0166
DSA-2901-1
MGASA-2014-0254

Affected Products

Wordpress