MEDIUM SEVERITY

CVE-2017-8295

Wordpress vulnerability

CVSS
5.9
EPSS
26.7%
EPSS pct
98th
Exploited
No known
WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for remote attackers to reset arbitrary passwords by making a crafted wp-login.php?action=lostpassword request and then arranging for this message to bounce or be resent, leading to transmission of the reset key to a mailbox on an attacker-controlled SMTP server. This is related to problematic use of the SERVER_NAME variable in wp-includes/pluggable.php in conjunction with the PHP mail function. Exploitation is not achievable in all cases because it requires at least one of the following: (1) the attacker can prevent the victim from receiving any e-mail messages for an extended period of time (such as 5 days), (2) the victim's e-mail system sends an autoresponse containing the original message, or (3) the victim manually composes a reply containing the original message.
Affected vendor
Wordpress
Affected product
Wordpress
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness type (CWE)
  • CWE-640 — Weak Password Recovery Mechanism
Published
2017-05-04

Risk analysis

Based on its CVSS vector, this vulnerability is exploitable over the network, high attack complexity, requiring no privileges, no user interaction. Successful exploitation leads to high impact to integrity.

Its EPSS score of 26.7% reflects a moderate probability of exploitation activity in the wild over the next 30 days, placing it above 98% of all scored CVEs.

Check your external exposure to CVE-2017-8295

  • Confirm whether Wordpress Wordpress is running on any internet-facing host or subdomain.
  • Match discovered service fingerprints against the version affected by CVE-2017-8295.
  • Prioritise remediation if the asset is public, business-critical, or near authentication/payment flows.

How ThreatPort helps with CVE-2017-8295

ThreatPort's external attack surface scanner checks your internet-facing assets — agentlessly, from the outside in — for the exposed services and versions that CVE-2017-8295 affects, then prioritises the finding by real risk using CISA KEV and FIRST.org EPSS.

Run a free external exposure scan

Are you exposed to CVE-2017-8295?

Run an instant, non-intrusive external scan to check your attack surface for CVE-2017-8295.

Start free scan

No credit card. Agentless.