CVE

Id
59111  
CVE No.
CVE-2012-5868  
Status
Candidate  
Description
WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator"s logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.  
Phase
Assigned (20121114)  
Votes
None (candidate not yet proposed)  
Comments