WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled.
42fcba1731c77d5cda678c7be995ec282e6c1c4bc17056f87826403d61243540