CVE-2017-17091: WordPress
High severity, CVSS 8.8. EPSS: 7% chance of exploitation in the next 30 days.
wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.
Affected products
- WordPress WordPress: up to and including 4.9
Published 2017-12-02. Last modified 2026-06-17.