web statistics

Wordpress 2.8.4 Security Release : Fixes Remote Password Reset Vulnerability

Posted on August 12th, 2009 under NEWS, WordPress
ADVERTISMENTS
Share |

I’ve read about a Wordpress Vulnerability at that a specially crafted URL like the one below could allow a remote password reset,bypassing the security check to verify a user requested a password reset with the new password sent to the email id provided by the unknown user, leaving you locked out of your own blog’s login.

http://www.domain.com/wp-login.php?action=lostpassword

wplogin

Wordpress 2.8.4 fixes this problem and is highly recommended to update immediately to Wordpress 2.8.4 to prevent such a attack.Though this does not allow remote access, unless your blog’s only user is admin which is commonly used.

Source : GHacks & Wordpress Blog.

Written by Avinash

Browse Tech Yard for the latest & interesting web applications, Freewares, Wordpress Tips, Firefox Hacks and Addons, Mobile Phones, Windows - Linux - MAC OS Tricks.

Stumble Digg Technorati Reddit Delicious


Related Posts

Leave a Reply

Subscribe to TECH YARD:

RSS

Grab the RSS feed for Free Updates!


subscribe

Get blog updates sent directly to your inbox by entering your email address above.



Recent Comments

Hey, anyone know if this is going to be available for Win7 any time soon? W...
Hi, thanks for the post, I am trying to modify this plugin to work on my sl...
It does not work with windows 7 please help...
I want to be able to pick and choose which applications are fetched during ...
hi this is good antiviruas soft...
Where can I find those input files? It doesn't say anywhere....
Very nice! Works exactly as described. Thank you!...
do you have any idea abt price???????...
Before I got my reliance connection, I have to search daily for free sms si...
I think we can find the Mobile operator using various online services also....