WordPress Exploit Allows Admin Password Reset

by WebWanderer on August 12, 2009

Shared by Dave

Alert to all WordPress blog users. Slashdot is reporting a vulnerability in WordPress 2.8.3.

You should get yours patched up to 2.8.4 ASAP.

Multiple readers have sent word of a vulnerability in WordPress 2.8.3 which allows anyone to lock an admin out of his or her account by resetting the password. “The bug … is trivial to exploit remotely using nothing more than a web browser and a specially manipulated link. Typically, requests to reset a password are handled using a registered email address. Using the special URL, the old password is removed and a new one generated in its place with no confirmation required.” An alert on the Full Disclosure mailing list detailed the vulnerability, and WordPress quickly rolled out version 2.8.4 to address the issue.

Read more of this story at Slashdot.

Be Sociable, Share!

Comments on this entry are closed.

Previous post:

Next post: