CVE-2009-2762
HIGH 7.5EPSS 19.6%
wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a check that assumes that $key is not an array.
- CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 19.64% chance of exploitation in the next 30 days, 97th percentile
- Nuclei
- high
- Published
- 2009-08-13
- Updated
- 2024-08-07
Proof-of-concept exploits (1)
Nuclei templates (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/9410
- https://www.exploit-db.com/exploits/6421
- https://www.exploit-db.com/exploits/6397