[wp-trac] [WordPress Trac] #38474: wp_signups.activation_key stores activation keys in plain text

WordPress Trac noreply at wordpress.org
Fri Oct 6 17:59:12 UTC 2017


#38474: wp_signups.activation_key stores activation keys in plain text
---------------------------------+------------------------------
 Reporter:  tomdxw               |       Owner:
     Type:  enhancement          |      Status:  new
 Priority:  normal               |   Milestone:  Awaiting Review
Component:  Security             |     Version:  4.6.1
 Severity:  normal               |  Resolution:
 Keywords:  has-patch 4.9-early  |     Focuses:  multisite
---------------------------------+------------------------------

Comment (by tomdxw):

 This weakness has been assigned CVE-2017-14990 by MITRE.

--
Ticket URL: <https://core.trac.wordpress.org/ticket/38474#comment:7>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list