wp-admin/user-new.php in WordPress before 4.9.1 sets the...
High severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Description
Published by the National Vulnerability Database
Dec 2, 2017
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 2, 2023
wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.
References