ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2014-5204”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2014-5204
Published
2014-08-18
CVSS:
-
ShadowTrackr CVSS:
0.0
Summary:
wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.