Description
In PHP version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00), testing a blank string as the password via password_verify() will incorrectly return true.
Remediation
References
Related Vulnerabilities
WordPress Plugin YouTube Embed Cross-Site Scripting (5.2.1)
MySQL CVE-2020-2761 Vulnerability (CVE-2020-2761)
WordPress Plugin Modern Events Calendar Lite Multiple Vulnerabilities (5.16.2)
WordPress Plugin fitness calculators Cross-Site Request Forgery (1.9.5)
WordPress Plugin WordPress Email Template Designer-WP HTML Mail Cross-Site Request Forgery (3.0.6)