CVE-2012-5868
Publication date 27 December 2012
Last updated 24 July 2024
Ubuntu priority
Description
WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator's logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| wordpress | 18.04 LTS bionic | Ignored |
| 16.04 LTS xenial | Ignored | |
| 14.04 LTS trusty | Not in release | |