peter bassill · operator
$ cve CVE-2007-6013 JSON

CVE-2007-6013

9.8
CRITICAL · CVSS 3.1 · EPSS 3.3% (pctl 88)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.28% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-327
On CISA KEVno
Public exploitnone known
Published2007-11-19
Last modified2026-06-16

Affected (2)

VendorProduct
fedoraprojectfedora
wordpresswordpress

References

→ the Explorer  ·  watch your stack  ·  NVD