Who Got Hacked This Week? May 12 Edition

Return To Article
Who Got Hacked This Week? May 12 Edition, slide 4

WordPress Flaw Allows Hackers to Reset Passwords

Researchers have discovered that WordPress is vulnerable to a logical vulnerability that could allow a remote attacker to reset user passwords.

The vulnerability is a result of the way WordPress processes password reset requests. An attacker can send a spoofed HTTP request while initiating the reset process in order to be sent the new password code.

Return To Article