High severity8.8NVD Advisory· Published Dec 2, 2017· Updated May 13, 2026
CVE-2017-17091
CVE-2017-17091
Description
wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.
Affected products
1- cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*Range: <=4.9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- codex.wordpress.org/Version_4.9.1nvdPatchRelease Notes
- github.com/WordPress/WordPress/commit/eaf1cfdc1fe0bdffabd8d879c591b864d833326cnvdPatch
- www.securityfocus.com/bid/102024nvdThird Party AdvisoryVDB Entry
- wpvulndb.com/vulnerabilities/8969nvdThird Party AdvisoryVDB Entry
- wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-release/nvdRelease Notes
- lists.debian.org/debian-lts-announce/2017/12/msg00019.htmlnvd
- www.debian.org/security/2018/dsa-4090nvd
News mentions
0No linked articles in our index yet.