peter bassill · operator
$ cve CVE-2012-0937 JSON

CVE-2012-0937 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 7.6% (pctl 94)

Patch early

A public exploit exists.

Description

wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier does not limit the number of MySQL queries sent to external MySQL database servers, which allows remote attackers to use WordPress as a proxy for brute-force attacks or denial of service attacks via the dbhost parameter, a different vulnerability than CVE-2011-4898. NOTE: the vendor disputes the significance of this issue because an incomplete WordPress installation might be present on the network for only a short time

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS7.63% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2012-01-30
Last modified2026-06-16

Affected (1)

VendorProduct
wordpresswordpress

Public exploits

SourceTitleDate
exploit-dbWordPress Core 3.3.1 - Multiple Vulnerabilities2012-01-25

References

→ the Explorer  ·  watch your stack  ·  NVD