|
WordPress issues new version, closes password flaw |
|
|
|
Source: SC Magazine - Posted by Anthony Pell
|
WordPress, the popular blogging software platform, has been updated to fix a flaw that could have enabled a hacker to change an administrator password.
The bug enables a specially crafted URL to evade a password reset security verification check, Matt Mullenweg, founding developer of WordPress, said Wednesday on the organization's blog.
“As a result, the first account without a key in the database (usually the admin account) would have its password reset and a new password would be emailed to the account owner," he said.
While annoying, the flaw would not permit a hacker to remotely access the blog's back-end -- unless they had access to the admin's email account to retrieve the password.
Read this full article at SC Magazine
Only registered users can write comments. Please login or register. Powered by AkoComment! |