CVE-2017-8295 | WordPress up to 4.8.3 Password Reset wp-login.php mail HOST password recovery (EDB-41963 / Nessus ID 100028)
A vulnerability, which was classified as critical, has been found in WordPress. Affected by this issue is the function mail of the file wp-login.php of the component Password Reset. The manipulation of the argument HOST as part of HTTP Header leads to weak password recovery.
This vulnerability is handled as CVE-2017-8295. The attack may be launched remotely. Furthermore, there is an exploit available.