HIGH
wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string
Published Dec 2, 2017
8.8
HIGHCVSS 3.0
EPSS 7.02%
Description
Affected products
Remediation
References (7)
Change history (0)
No recorded changes yet.