vendor:
WordPress
by:
john@secureli.com
7,5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: WordPress
Affected Version From: <= v4.0
Affected Version To: None
Patch Exists: YES
Related CWE: CVE-2014-9034
CPE: a:wordpress:wordpress
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
WordPress <= v4.0 Denial of Service Vulnerability
A denial of service vulnerability exists in WordPress versions prior to 4.0. An attacker can send a large number of POST requests with a large username and password to the wp-login.php page, which will cause the server to become unresponsive. This can be done by using the proof-of-concept code developed by john@secureli.com.
Mitigation:
Upgrade to WordPress version 4.0 or later.