CVE-2017-5493: Weak RNG
wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPressto a version that resolves this vulnerability.Fixed in 4.7.1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5493?
CVE-2017-5493 has been rated as a Medium severity vulnerability.
How do I fix CVE-2017-5493?
To fix CVE-2017-5493, upgrade your WordPress installation to version 4.7.1 or later.
What type of vulnerability is CVE-2017-5493?
CVE-2017-5493 is a cryptographic vulnerability that affects the random number generation for keys in WordPress.
Who is affected by CVE-2017-5493?
Users of WordPress versions prior to 4.7.1 are affected by CVE-2017-5493.
Can CVE-2017-5493 be exploited remotely?
Yes, CVE-2017-5493 can be exploited remotely by attackers to bypass access restrictions.