Wordpress Core < 4.0.1 - Hash Collision
2014-11-20 00:00
David AndersonStrategic Overview
StatusPatched in 3.7.5
Affected CoreWordPress 4.0
Affected Version
3.7 – 4.0 · 5 branchesCVSS8.1High
CVE
CVE-2014-9037Vulnerability Overview
WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.
Technical Analysis
REMEDIATION: Update to one of the following versions, or a newer patched version: 3.7.5, 3.8.5, 3.9.3, 4.0.1 --- IDENTIFIER: CWE-916 (Use of Password Hash With Insufficient Computational Effort) The product generates a hash for a password, but it uses a scheme that does not provide a sufficient level of computational effort that would make password cracking attacks infeasible or expensive.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C