D
djbaxter
Guest
WordPress <= 2.8.3 Reset Admin Password Vulnerability
by DK
August 11, 2009
...more
Upgrade to WordPress 2.84 either automatically via your Admin Control Panel or download and manually install WordPress 2.84 here.
by DK
August 11, 2009
An exploit has been released for all current versions of WordPress including WordPress <= 2.8.3.
Laurent Gaffi? who published the finding says:
An attacker could exploit this vulnerability to compromise the adminFrom what I can tell the vulnerability allows an attacker to reset the admin user account without having a valid email address. This could certainly be used in a denial of service vulnerability, locking an admin out their site by continually changing the password.
account of any wordpress/wordpress-mu <= 2.8.3
...more
Upgrade to WordPress 2.84 either automatically via your Admin Control Panel or download and manually install WordPress 2.84 here.