WordPress password reset flaw patched in 2.8.4

Posted By: Wayne Schulz    



wordpress.jpg

Yesterday my friend Robert Wood reset the administrative password on my site. Rather than be upset – I’m delighted. Robert was notifying me of a flaw in the WordPress software that allowed anyone to reset the administrative password of a blog.

While this did not provide access to the administrative account (the password reset was only sent out via email to the registered account holder) – it did expose a weakness. If someone also had access to the email account affiliated with the administrator they could potentially hijack this password reset and gain access to your WordPress site.

Version 2.8.4 of WordPress is available and I recommend you upgrade immediately.

WordPress via Robert Wood- DDF Consulting – Florida MAS 90 Consultant

© 2009, Wayne Schulz. All rights reserved. Sage 50, Sage 100, Sage 300 and Sage 500 are registered trademarks of Sage. Have additional unanswered questions about MAS90? You may contact Schulz Consulting here.

We publish an email newsletter each Tuesday at 3pm – join here.


Related posts you might want to review:

  1. RoboForm Password Manager $10.40 off through 4/15/09
  2. Why I use, love and adore Gmail
  3. Schulz Consulting Email Newsletter Archives Now Online

Comments

Comments are closed.