IsItPatchedInstant security status for any software version
← All products

CVE-2014-9034

MEDIUM severity · CVSS 5 · CWE-19
5CVSS MEDIUM

Summary

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.

Impact & exploitability

Attack vectorNetwork
Attack complexityLow
Privileges required
User interaction
Confidentiality impactNone
Integrity impactNone
Availability impact
Exploit probability (EPSS)80%

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: https://wordpress.org/news/2014/11/wordpress-4-0-1/ ↗

Last checked: Wed, 10 Jun 2026 22:18:30 UTC