Cross-Site Request Forgery Vulnerability in WordPress by Automattic
CVE-2014-5204

Currently unrated

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
18 August 2014

What is CVE-2014-5204?

A vulnerability has been identified in the WordPress platform where the CSRF protection mechanism does not consistently reject invalid CSRF nonces. Specifically, the rejection timing differs based on which characters in the nonce are incorrect, enabling attackers to optimize brute-force attacks, potentially allowing unauthorized actions on behalf of legitimate users.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.