Thu. Apr 25th, 2024

Another day, another vulnerability with WordPress.  Make sure you apply the latest patch, because according to the WordPress blog, the latest vulnerability permits a situation where a specially crafted URL could be requested that would allow an attacker to bypass a security check to verify a user requested a password reset. As a result, the first account without a key in the database (usually the admin account) would have its password reset and a new password would be emailed to the account owner. This doesn’t allow remote access, but it is very annoying.

By admin

Leave a Reply