CVE-2005-2109: Medium severity WordPress vulnerability
wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2109?
CVE-2005-2109 has been classified as a medium severity vulnerability due to its potential to affect the integrity of password reset emails.
How do I fix CVE-2005-2109?
To fix CVE-2005-2109, update your WordPress installation to the latest version that addresses this vulnerability.
What versions of WordPress are affected by CVE-2005-2109?
CVE-2005-2109 affects WordPress versions 1.5.1.2 and earlier, including 1.0, 1.0.1, 1.0.2, 1.2, 1.5, and 1.5.1.
What attack vector does CVE-2005-2109 utilize?
CVE-2005-2109 can be exploited remotely by attackers to manipulate the content of forgotten password email messages.
What are the potential impacts of exploiting CVE-2005-2109?
Exploiting CVE-2005-2109 could allow an attacker to send misleading password reset emails, possibly leading to unauthorized access.