CVE-2014-9037: Debian Linux
Medium severity, CVSS 6.8. EPSS: 2.6% chance of exploitation in the next 30 days.
WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.
Affected products
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Mageia Project Mageia: version 3 only; version 4 only
- WordPress WordPress: up to and including 3.7.4; version 3.8 only; version 3.8.1 only; version 3.8.2 only; version 3.8.3 only; version 3.8.4 only; …
Published 2014-11-25. Last modified 2026-06-17.