The versions of WordPress before 3.7.2 and 3.8.2 have a vulnerability which makes it easier for attackers to gain access to a website with a forged authentication cookie. The issue is in the wp_validate_auth_cookie function in the wp-includes/pluggable.php file.