The use of non-strict comparison in WordPress’s cookie validation code could allow an attacker to forge authentication cookies by exploiting PHP’s type juggling system or by measuring timing differences between requests. Both attacks are a bit impractical, but rather fun.
read more......https://labs.mwrinfosecurity.com/blog/2014/04/11/wordpress-auth-cookie-forgery/
read more......https://labs.mwrinfosecurity.com/blog/2014/04/11/wordpress-auth-cookie-forgery/