CVE-2017-9064: CSRF
Published May 18, 2017
·Updated
In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not required for updating credentials.
Affected Software
3 affected components
WordPress WordPress<=4.7.4
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
May 18, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9064?
CVE-2017-9064 has been classified as a medium severity vulnerability due to its potential to allow unauthorized actions.
2
How do I fix CVE-2017-9064?
To fix CVE-2017-9064, update WordPress to version 4.7.5 or later to mitigate the Cross Site Request Forgery risk.
3
Which versions of WordPress are affected by CVE-2017-9064?
CVE-2017-9064 affects WordPress versions before 4.7.5, specifically all versions up to and including 4.7.4.
4
What type of vulnerability is CVE-2017-9064?
CVE-2017-9064 is a Cross Site Request Forgery (CSRF) vulnerability related to filesystem credentials in WordPress.
5
Are Debian systems vulnerable to CVE-2017-9064?
Yes, CVE-2017-9064 affects Debian Linux versions 8.0 and 9.0 if WordPress is installed on those systems.