CVE-2014-9037

Source
https://nvd.nist.gov/vuln/detail/CVE-2014-9037
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2014-9037.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2014-9037
Downstream
Related
Published
2014-11-25T23:59:08Z
Modified
2025-08-09T20:01:26Z
Summary
[none]
Details

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.

References

Affected packages