Feed/CVE-2012-5868
CVE-2012-5868LOWCVSS 2.6

CVE-2012-5868

Published Dec 27, 2012·Updated Jun 16, 2026

NVD Description

WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.

CVSS Vector

AV:N/AC:H/Au:N/C:P/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free