WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-10-02T17:00:00
Updated: 2024-08-05T19:42:22.357Z
Reserved: 2017-10-02T00:00:00
Link: CVE-2017-14990
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-10-03T01:29:03.013
Modified: 2024-11-21T03:13:54.420
Link: CVE-2017-14990
Redhat
No data.