CVE-2017-8295 is a medium-severity vulnerability affecting WordPress through version 4.7.4, allowing remote attackers to reset arbitrary user passwords. This flaw arises from WordPress's reliance on the Host HTTP header for password reset emails, enabling an attacker to redirect the reset key to a controlled SMTP server under specific conditions. Exploitation requires high attack complexity, as it depends on the victim's email system behavior or prolonged email unavailability. While not listed on CISA's KEV, exploit code is publicly available, and the vulnerability has garnered significant community discussion and media coverage, indicating substantial interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.7.4CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.