VYPR
Critical severity9.8NVD Advisory· Published Nov 19, 2007· Updated Jun 16, 2026

CVE-2007-6013

CVE-2007-6013

Description

Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*range: >=1.5,<=2.3.1
    • (no CPE)range: 1.5 - 2.3.1
  • cpe:2.3:o:fedoraproject:fedora:7:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:7:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

13

News mentions

0

No linked articles in our index yet.