CVE detail
CVE-2006-6017 — CVE-2006-6017
Published 2006-11-21 · Modified 2026-06-16 · Vendor wordpress · Product wordpress · Source nvd
MEDIUM
severity
CVSS-derived band
0.0226
EPSS probability
exploitation probability, 30d
81.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed or (2) large serialized object, because the object triggers automatic unserialization for display.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References