WordPress Cookie Integrity Protection Privilege Escalation Vulnerability
RISK: Medium Risk
A vulnerability has been identified in WordPress, which could be exploited by attackers to compromise an affected web site. This issue is caused by an error in the MAC calculation procedure when handling the "USERNAME" and "EXPIRY_TIME" parameters contained in the authentication cookie, which could be exploited by attackers to gain unauthorized administrative access (and execute arbitrary PHP code) by creating an account with a specially crafted username.
Impact
- Elevation of Privilege
System / Technologies affected
- WordPress versions prior to 2.5.1
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Upgrade to WordPress version 2.5.1 :
http://wordpress.org/download/
Vulnerability Identifier
Source
Related Link
Share with