Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
History

Wed, 28 May 2025 14:30:00 +0000

Type Values Removed Values Added
References

Thu, 22 May 2025 04:30:00 +0000


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-11-19T21:00:00

Updated: 2024-08-07T15:54:25.756Z

Reserved: 2007-11-19T00:00:00

Link: CVE-2007-6013

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2007-11-19T21:46:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2007-6013

cve-icon Redhat

Severity : Important

Publid Date: 2007-11-19T00:00:00Z

Links: CVE-2007-6013 - Bugzilla