AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2012-6707

HIGH · CVSS 7.5 EPSS 1.11%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2017-10-19 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It affects WordPress.

CVE
CVE-2012-6707
Severity
HIGH
CVSS
7.5
EPSS
1.11%
WordPress

Original NVD Description

WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a WordPress site from a web host that uses a recent PHP version to a different web host that uses PHP 5.2. These use cases are plausible (but very unlikely) based on statistics showing widespread deployment of WordPress with obsolete PHP versions.

Related CVEs

Other vulnerabilities affecting the same vendor(s)