CVE-2014-9039: Medium severity debian linux vulnerability
wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9039?
CVE-2014-9039 has a medium severity rating, as it allows remote attackers to reset passwords if they gain access to the victim's email account.
How do I fix CVE-2014-9039?
To fix CVE-2014-9039, update your WordPress installation to version 4.0.1 or later.
What versions of WordPress are affected by CVE-2014-9039?
CVE-2014-9039 affects WordPress versions prior to 3.7.5, all versions of 3.8.x before 3.8.5, all versions of 3.9.x before 3.9.3, and 4.x before 4.0.1.
Can CVE-2014-9039 be exploited without user interaction?
Yes, CVE-2014-9039 can be exploited without user interaction by an attacker who has access to the victim's email.
What type of vulnerability is CVE-2014-9039?
CVE-2014-9039 is classified as an access control vulnerability that enables password reset attacks.