Brute Force Vulnerability in Session Management for WordPress
CVE-2025-48461
5MEDIUM
What is CVE-2025-48461?
This vulnerability allows unauthenticated users to exploit predictable session cookies within the WordPress platform. As a result, attackers can perform brute force guessing attacks that may lead to unauthorized account takeover, enabling them to gain root, admin, or user privileges. This flaw poses a serious risk as it could allow malicious actors to reset passwords and compromise sensitive information.
Affected Version(s)
Advantech Wireless Sensing and Equipment (WISE) A2.01 B00
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Joel Chang Zhi Kai
