CVE-2014-6412: WordPress

High severity, CVSS 8.1. EPSS: 4.6% chance of exploitation in the next 30 days.

WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.

Affected products

  • WordPress WordPress: before 4.4.0 (fixed in 4.4.0)

Published 2018-04-12. Last modified 2026-06-17.