WordPress Core - Informational < 6.8 - Weak Hashing Algorithm

Weak Encoding for Password
CVE CVE-2012-6707
CVSS Low (3.7)
Publicly Published June 20, 2012
Last Updated May 12, 2025
Description

Versions of WordPress core older than version 6.8 use a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a WordPress site from a web host that uses a recent PHP version to a different web host that uses PHP 5.2. These use cases are plausible (but very unlikely) based on statistics showing widespread deployment of WordPress with obsolete PHP versions.

References

1 affected software package

Software Type Core
Software Slug wordpress (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 6.8
Patched Version
  • 6.8
This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.
License: Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. License Detail.