Back

CRITICAL

wordpress cookie authentication vulnerability

Published Nov 19, 2007

Description

Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 19, 2007
Updated Aug 7, 2024
Reserved Nov 19, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Nov 19, 2007