CVE-2017-5493 is a high-severity vulnerability affecting WordPress versions prior to 4.7.1, specifically within the wp-includes/ms-functions.php component of the Multisite API. It stems from improper random number generation for keys, allowing remote attackers to bypass access restrictions during site or user signups. With a CVSS v3 score of 7.5, this vulnerability is easily exploitable over the network with low attack complexity, potentially leading to high integrity impact without requiring user interaction. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, and community discussion and media coverage are minimal, its FAUCET Risk Score of 58/100 indicates a notable risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.7CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.