CVE-2014-6412: WordPress
High severity, CVSS 8.1. EPSS: 4.6% chance of exploitation in the next 30 days.
WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.
Affected products
- WordPress WordPress: before 4.4.0 (fixed in 4.4.0)
Published 2018-04-12. Last modified 2026-06-17.