Description
WordPress is prone to a Denial of Service vulnerability which can be exploited by malicious people to cause the affected website to consume memory and CPU resources, thus denying service to legitimate users. WordPress versions prior to 3.7.4, 3.8.4 and 3.9.2 are vulnerable.
Remediation
Update to WordPress version 3.7.4, 3.8.4, 3.9.2 or latest
References
http://www.breaksec.com/?p=6362
http://codex.wordpress.org/Version_3.7.4
Related Vulnerabilities
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6311)
WordPress Plugin Limit Login Attempts Reloaded Security Bypass (2.7.4)
WordPress Plugin blogVault Real-time Backup PHP Object Injection (1.44)
WordPress Plugin Mikiurl WordPress Eklentisi Cross-Site Request Forgery (2.0)