FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

wordpress -- multiple vulnerabilities

Affected packages
wordpress < 3.7.5,1
3.8,1 <= wordpress < 3.8.5,1
3.9,1 <= wordpress < 3.9.3,1
4.0,1 <= wordpress < 4.0.1,1
zh-wordpress < 3.7.5
3.8 <= zh-wordpress < 3.8.5
3.9 <= zh-wordpress < 3.9.3
4.0 <= zh-wordpress < 4.0.1
de-wordpress < 3.7.5
3.8 <= de-wordpress < 3.8.5
3.9 <= de-wordpress < 3.9.3
4.0 <= de-wordpress < 4.0.1
ja-wordpress < 3.7.5
3.8 <= ja-wordpress < 3.8.5
3.9 <= ja-wordpress < 3.9.3
4.0 <= ja-wordpress < 4.0.1
ru-wordpress < 3.7.5
3.8 <= ru-wordpress < 3.8.5
3.9 <= ru-wordpress < 3.9.3
4.0 <= ru-wordpress < 4.0.1

Details

VuXML ID 5e135178-8aeb-11e4-801f-0022156e8794
Discovery 2014-11-25
Entry 2015-01-05

MITRE reports:

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.

wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.

Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a post.

Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.

Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords.

References

CVE Name CVE-2014-9033
CVE Name CVE-2014-9034
CVE Name CVE-2014-9035
CVE Name CVE-2014-9036
CVE Name CVE-2014-9037
CVE Name CVE-2014-9038
CVE Name CVE-2014-9039