CVE
- Id
- 59111
- CVE No.
- CVE-2012-5868
- Status
- Candidate
- Description
- WordPress 3.4.2 does not invalidate a wordpress_sec session cookie upon an administrator"s logout action, which makes it easier for remote attackers to discover valid session identifiers via a brute-force attack, or modify data via a replay attack.
- Phase
- Assigned (20121114)
- Votes
- None (candidate not yet proposed)
- Comments