CVE-2014-6412 describes a vulnerability in WordPress versions prior to 4.4, where a weakness in password-recovery token generation allows remote attackers to predict these tokens through brute-force attacks. With a CVSS score of 8.1 (HIGH), this vulnerability has a network attack vector and high impact on confidentiality, integrity, and availability, despite a high attack complexity. While no public exploit code is readily available (Metasploit, Nuclei, ExploitDB), and it's not on CISA's KEV catalog, the vulnerability has received some community discussion and media attention, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.4.0CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.