Total vulnerabilities in the database
The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison for widgets, which allows remote attackers to conduct a timing side-channel attack by measuring the delay before inequality is calculated.
Software | From | Fixed in |
---|---|---|
WordPress / wordpress | - | 4.2.3.x |