CVE-2013-2173

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
21/06/2013
Last modified:
11/04/2025

Description

wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of service (CPU consumption) via a crafted value of a certain wp-postpass cookie.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wordpress:wordpress:3.5.1:*:*:*:*:*:*:*