Wordpress Core < 4.0.1 - Hash Collision

2014-11-20 00:00
David Anderson

Strategic Overview

Status
Patched in 3.7.5
Affected CoreWordPress 4.0
Affected Version3.7 – 4.0 · 5 branches
CVSS8.1High
CVECVE-2014-9037
View all WordPress 4.0 vulnerabilities

Vulnerability Overview

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.

Technical Analysis

REMEDIATION: Update to one of the following versions, or a newer patched version: 3.7.5, 3.8.5, 3.9.3, 4.0.1 --- IDENTIFIER: CWE-916 (Use of Password Hash With Insufficient Computational Effort) The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C