WordPress versions 1.5 through 2.3.1 use a method to store passwords that makes it possible for attackers to get around the authentication process. This is done by taking the MD5 hash of a password from the user database and using it to create the authentication cookie.