CVE-2017-14990
published 2017-10-03CVE-2017-14990: WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it…
PriorityP339medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
2.42%
82.4th percentile
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | wordpress | < wordpress 4.8.2+dfsg-2 (bookworm) | wordpress 4.8.2+dfsg-2 (bookworm) |
| wordpress | wordpress | — | — |
| wordpress | wordpress | >= 0 < 4.8.2+dfsg-2 | 4.8.2+dfsg-2 |
| wordpress | wordpress | >= 0 < 4.8.2+dfsg-2 | 4.8.2+dfsg-2 |
| wordpress | wordpress | >= 0 < 4.8.2+dfsg-2 | 4.8.2+dfsg-2 |
| wordpress | wordpress | >= 0 < 4.8.2+dfsg-2 | 4.8.2+dfsg-2 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vhx7-jpm9-345w: WordPress 4
ghsa_unreviewed·2022-05-13
CVE-2017-14990 [MEDIUM] CWE-312 GHSA-vhx7-jpm9-345w: WordPress 4
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).
OSV
CVE-2017-14990: WordPress 4
osv·2017-10-03·CVSS 6.5
CVE-2017-14990 [MEDIUM] CVE-2017-14990: WordPress 4
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).
Debian
CVE-2017-14990: wordpress - WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores th...
vendor_debian·2017·CVSS 6.5
CVE-2017-14990 [MEDIUM] CVE-2017-14990: wordpress - WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores th...
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).
Scope: local
bookworm: resolved (fixed in 4.8.2+dfsg-2)
bullseye: resolved (fixed in 4.8.2+dfsg-2)
forky: resolved (fixed in 4.8.2+dfsg-2)
sid: resolved (fixed in 4.8.2+dfsg-2)
trixie: resolved (fixed in 4.8.2+dfsg-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-10-03
Published