CVE-2017-5491: WordPress

Medium severity, CVSS 5.3. EPSS: 3.2% chance of exploitation in the next 30 days.

wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.

Affected products

Published 2017-01-15. Last modified 2026-06-17.