wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Link | Tags |
---|---|
https://www.debian.org/security/2018/dsa-4090 | vendor advisory |
https://wpvulndb.com/vulnerabilities/8969 | third party advisory vdb entry |
https://lists.debian.org/debian-lts-announce/2017/12/msg00019.html | mailing list |
http://www.securityfocus.com/bid/102024 | third party advisory vdb entry |
https://codex.wordpress.org/Version_4.9.1 | patch release notes |
https://github.com/WordPress/WordPress/commit/eaf1cfdc1fe0bdffabd8d879c591b864d833326c | patch |
https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/ | release notes |