CVE-2007-6013
Last modified
CVE-2007-6013 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.. EPSS estimates a 3.28% chance of exploitation in the next 30 days.
Description
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wordpress | Wordpress | >= 1.5, <= 2.3.1 |
| Fedoraproject | Fedora | 7 |
| Fedoraproject | Fedora | 8 |
References
- https://osvdb.org/40801Broken Link
- https://secunia.com/advisories/27714Broken Link, Vendor Advisory
- https://secunia.com/advisories/28310Broken Link, Vendor Advisory
- https://trac.wordpress.org/ticket/5367Exploit, Issue Tracking
- https://www.cl.cam.ac.uk/~sjm217/advisories/wordpress-cookie-auth.txtThird Party Advisory
- https://www.securityfocus.com/archive/1/483927/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securitytracker.com/id?1018980Broken Link, Third Party Advisory, VDB Entry
- https://www.vupen.com/english/advisories/2007/3941Broken Link, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38578Third Party Advisory, VDB Entry
- https://osvdb.org/40801Broken Link
- https://secunia.com/advisories/27714Broken Link, Vendor Advisory
- https://secunia.com/advisories/28310Broken Link, Vendor Advisory
- https://trac.wordpress.org/ticket/5367Exploit, Issue Tracking
- https://www.cl.cam.ac.uk/~sjm217/advisories/wordpress-cookie-auth.txtThird Party Advisory
- https://www.securityfocus.com/archive/1/483927/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- https://www.securitytracker.com/id?1018980Broken Link, Third Party Advisory, VDB Entry
- https://www.vupen.com/english/advisories/2007/3941Broken Link, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38578Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-6013?
How severe is CVE-2007-6013?
How do I fix CVE-2007-6013?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-6007Integer overflow in the ID_PSP.apl plug-in for ACD ACDSee Ph…
- CVE-2007-6008Heap-based buffer overflow in emlsr.dll before 2.0.0.4 in Au…
- CVE-2007-6009Multiple buffer overflows in ACD products allow user-assiste…
- CVE-2007-6010Unspecified vulnerability in pioneers (formerly gnocatan) 0.…
- CVE-2007-6011Unspecified vulnerability in main.php of BugHotel Reservatio…
- CVE-2007-6012SQL injection vulnerability in SearchR.asp in DocuSafe 4.1.0…
- CVE-2007-6014SQL injection vulnerability in post.php in Beehive Forum 0.7…
- CVE-2007-6015Stack-based buffer overflow in the send_mailslot function in…
- CVE-2007-6016Multiple stack-based buffer overflows in the PVATLCalendar.P…
- CVE-2007-6017The PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar…
- CVE-2007-6018IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5,…
- CVE-2007-6019Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and e…
Are you affected by CVE-2007-6013?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
