cbcvebase.
CVE-2017-14990
published 2017-10-03

CVE-2017-14990: WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it…

PriorityP339medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
2.42%
82.4th percentile
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianwordpress< wordpress 4.8.2+dfsg-2 (bookworm)wordpress 4.8.2+dfsg-2 (bookworm)
wordpresswordpress
wordpresswordpress>= 0 < 4.8.2+dfsg-24.8.2+dfsg-2
wordpresswordpress>= 0 < 4.8.2+dfsg-24.8.2+dfsg-2
wordpresswordpress>= 0 < 4.8.2+dfsg-24.8.2+dfsg-2
wordpresswordpress>= 0 < 4.8.2+dfsg-24.8.2+dfsg-2

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.