wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.
References
Configurations
History
No history.
Information
Published : 2017-01-15 02:59
Updated : 2019-10-03 00:03
NVD link : CVE-2017-5491
Mitre link : CVE-2017-5491
CVE.ORG link : CVE-2017-5491
JSON object : View
Products Affected
wordpress
- wordpress
CWE
CWE-1188
Initialization of a Resource with an Insecure Default