VDB

DEBIAN-CVE-2014-9037

DEBIAN-CVE-2014-9037 PUBLISHED

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.

Affected Products

VendorProductVersions
Debian:14wordpress0, 0
Debian:11wordpress0, 0, 0
Debian:13wordpress0, 0, 0
Debian:12wordpress0, 0, 0

Timeline

  • Nov 25, 2014 CVE Published
  • Aug 8, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›