• Hi,

    I’m experiencing random severe latency on a WordPress website using ASE.

    During profiling, I found that some frontend requests can take around 123 seconds to complete.

    Example:

    • Total request time: 122,994 ms
    • wp-includes/pluggable.php -> wp_check_password(): 120,760 ms
    • Elementor: ~875 ms
    • Database queries: ~150 ms
    • cURL: ~230 ms

    I searched the codebase for calls to wp_check_password() and found the frontend Password Protection module here:

    wp-content/plugins/admin-site-enhancements/classes/class-password-protection.php

    around line 162.

    The code appears to retrieve the asenha_password_protection cookie and use it as the hash parameter passed to wp_check_password().

    A normal bcrypt benchmark on the same server gives:

    PASSWORD_BCRYPT cost 10: ~79 ms

    So the server itself does not appear to have a bcrypt performance issue.

    This makes me suspect that a malformed or unusually expensive bcrypt hash stored in the asenha_password_protection cookie could cause wp_check_password() to consume a very large amount of CPU time.

    The issue is intermittent, which would also be consistent with the request depending on the cookie value.

    Disabling ASE Password Protection and replacing it with HTTP Basic Auth / .htpasswd appears to be a suitable workaround.

    Could you please review whether the cookie value should be validated before it is passed to wp_check_password()?

    In particular, it may be worth checking:

    • that the hash has the expected format
    • that the bcrypt cost is within an acceptable range
    • that malformed/unexpected cookie values are rejected before password verification

    I can provide profiling screenshots and additional testing if needed.

    Thanks,

Viewing 5 replies - 1 through 5 (of 5 total)
  • Plugin Author Bowo

    (@qriouslad)

    @okparfait Thank you for reporting this in great detail. Will investigate. By the way, are you on the latest version of ASE?

    Thread Starter okparfait

    (@okparfait)

    Yes !

    ASE : 9.1.4
    PHP : 8.5
    WordPress : 7.1.2

    Plugin Author Bowo

    (@qriouslad)

    @okparfait Noted. I can confirm that the asenha_password_protection cookie was passed straight to wp_check_password() as the hash, so a well-formed bcrypt hash with a high cost could tie up the request for about two minutes. In the next release, scheduled for next Monday, the cookie will be a fixed-cost HMAC and anything that is not 64-character hex value is rejected before any password hashing runs. Please test when you see it.

    • This reply was modified 3 days, 22 hours ago by Bowo.
    Thread Starter okparfait

    (@okparfait)

    Thanks for confirming.
    I’ll test the next release when it’s available!

    Plugin Author Bowo

    (@qriouslad)

    @okparfait v9.2.0 has just been released. Please test when you see it.

Viewing 5 replies - 1 through 5 (of 5 total)

You must be logged in to reply to this topic.