Junglewise Threat Intelligence

CVE-2017-5491: WordPress bypass of posting restrictions in wp-mail.php

CVE-2017-5491 · Severity: medium · CVSS 5.3 · Published 2017-01-15

Technologies: Wordpress. Vendors: Wordpress.

Executive brief

WordPress includes a feature that allows users to publish blog posts by sending an email to a specific address. A vulnerability in this feature could allow an unauthorized person to post content to a website by spoofing a default mail server address. This could lead to unauthorized content being published on the site, potentially damaging the organization's reputation or spreading misinformation.

Technical details

The 'Post via Email' functionality in WordPress (wp-mail.php) fails to properly validate the mail server source when default configuration settings are in place. Specifically, if the 'mailserver_url' setting is left as the default 'mail.example.com', an attacker can spoof a mail server with that name to bypass intended posting restrictions. This allows unauthenticated remote attackers to inject and publish posts on the affected WordPress site. The issue was addressed in version 4.7.1 by disabling wp-mail.php functionality when the default mail server URL is detected.

Affected products

  • WordPress WordPress < 4.7.1

Timeline

  • 2017-01-11: patched: WordPress version 4.7.1 released
  • 2017-01-14: disclosed: Public disclosure via oss-security mailing list
  • 2017-01-15: advisory: NVD publication date

References

Related threats