Wordpress 1.5 through 2.3.1 uses cookie values based on...
Moderate severity
Unreviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Feb 18, 2024
Description
Published by the National Vulnerability Database
Nov 19, 2007
Published to the GitHub Advisory Database
May 1, 2022
Last updated
Feb 18, 2024
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
References