wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.
References
Configurations
Information
Published : 2017-01-14 18:59
Updated : 2019-10-02 17:03
NVD link : CVE-2017-5491
Mitre link : CVE-2017-5491
JSON object : View
CWE
CWE-1188
Insecure Default Initialization of Resource
Products Affected
wordpress
- wordpress