Skip to main content

CVE-2014-9034

CVSS Score Not Available
72.48%
HIGH RiskEPSS (99th percentile)

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.

Published: 11/25/2014
Modified: 4/12/2025
Back to CVE Lookup

Vulnerability Summary

EPSS Score (Exploitation Probability)

72.48%HIGH Exploitation Risk
99th percentile

This vulnerability has a 72.48% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.