CVE-2014-5204
Status: ModifiedMedium (6.8)—
wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
- Base score: 6.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.85%
- Percentile among all scored CVEs: 78
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
CWEs
- CWE-352
References
- http://openwall.com/lists/oss-security/2014/08/13/3
- http://www.debian.org/security/2014/dsa-3001
- https://core.trac.wordpress.org/changeset/29384
- https://wordpress.org/news/2014/08/wordpress-3-9-2/
- http://openwall.com/lists/oss-security/2014/08/13/3
- http://www.debian.org/security/2014/dsa-3001
- https://core.trac.wordpress.org/changeset/29384
- https://wordpress.org/news/2014/08/wordpress-3-9-2/
Raw JSON (NVD)
Show
{
"id": "CVE-2014-5204",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-08-18T11:15:26.403",
"references": [
{
"url": "http://openwall.com/lists/oss-security/2014/08/13/3",
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2014/dsa-3001",
"source": "cve@mitre.org"
},
{
"url": "https://core.trac.wordpress.org/changeset/29384",
"source": "cve@mitre.org"
},
{
"url": "https://wordpress.org/news/2014/08/wordpress-3-9-2/",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://openwall.com/lists/oss-security/2014/08/13/3",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2014/dsa-3001",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://core.trac.wordpress.org/changeset/29384",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://wordpress.org/news/2014/08/wordpress-3-9-2/",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack."
},
{
"lang": "es",
"value": "wp-includes/pluggable.php en WordPress anterior a 3.9.2 rechaza cadenas de caracteres de un sólo uso CSRF inválidos con diferencias de tiempo dependiendo de qué caracteres en la cadena de caracteres de un sólo uso sean incorrectos, lo que facilita a atacantes remotos evadir un mecanismo de protección CSRF a través de un ataque de fuerza bruta."
}
],
"lastModified": "2026-06-17T00:11:12.657",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16F59A04-14CF-49E2-9973-645477EA09DA"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "57BFE6B1-2105-44A7-A07C-4EAF50741F03",
"versionEndIncluding": "3.9.1"
},
{
"criteria": "cpe:2.3:a:wordpress:wordpress:3.9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CB4D4609-5AD6-44F3-B991-74E35A7E5C2D"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}