CVE-2017-5491: WordPress
Medium severity, CVSS 5.3. EPSS: 3.2% chance of exploitation in the next 30 days.
wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed mail server with the mail.example.com name.
Affected products
- WordPress WordPress: up to and including 4.7
Published 2017-01-15. Last modified 2026-06-17.