CVE-2012-6707
📛 CVE Title
Ubuntu: (CVE-2012-6707): wordpress vulnerability
Description
WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a WordPress site from a web host that uses a recent PHP version to a different web host that uses PHP 5.2. These use cases are plausible (but very unlikely) based on statistics showing widespread deployment of WordPress with obsolete PHP versions.
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- MEDIUM
- CVSS score
- 5.0 / 10
- CVSS vector
AV:N/AC:L/Au:N/C:P/I:N/A:N- Effective score
- 5.0 / 10 MEDIUM source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- 2017-10-19 00:00 UTC
- Last updated
- —
- Source
- https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2012-6707/
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2017-10-19 19:29:00 UTC
- NVD last modified
- 2026-06-16 23:48:38 UTC
- EPSS score
- 0.0111 (probability of exploitation in next 30 days)
- EPSS percentile
- 62.68% vs all CVEs — higher = more likely to be exploited, as of 2026-08-04
NVD-assigned CWE(s):
CWE-326
(differs from the CNA list above)
NVD / KEV / EPSS data refreshed 2026-08-04 21:07 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2012-6549 - Assigner
- mitre
- Published
- Oct 19, 2017, 7:00:00 PM
- Updated
- Sep 17, 2024, 12:51:05 AM
- EUVD-reported EPSS
- 1.1100
- Vendors
- n/a
- Products
-
n/a (n/a)
- Aliases
-
GHSA-75fw-m5qw-hfx6
ENISA description: WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values. NOTE: the approach to changing this may not be fully compatible with certain use cases, such as migration of a WordPress site from a web host that uses a recent PHP version to a different web host that uses PHP 5.2. These use cases are plausible (but very unlikely) based on statistics showing widespread deployment of WordPress with obsolete PHP versions.
EUVD references (1)
Affected products — CPE 2.3 (1) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (5)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- http://cwe.mitre.org/data/definitions/326.html rapid7:cwe.mitre.org
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2012-6549 rapid7:euvd.enisa.europa.eu
- https://attackerkb.com/topics/CVE-2012-6707 rapid7:attackerkb.com
- https://core.trac.wordpress.org/ticket/21022 rapid7:core.trac.wordpress.org
- https://www.cve.org/CVERecord?id=CVE-2012-6707 rapid7:www.cve.org
NVD-tagged references (2)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://core.trac.wordpress.org/ticket/21022 cve@mitre.org Issue TrackingPatchVendor Advisory
- https://core.trac.wordpress.org/ticket/21022 af854a3a-2127-422b-91ae-364da2661108 Issue TrackingPatchVendor Advisory
Remediations (1)
-
rapid7
wordpress-upgrade-4_8_3
2026-06-01 20:05 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.