
WordPress Flaw Allows Hackers to Reset Passwords
Researchers have discovered that WordPress is vulnerable to a logical vulnerability that could allow a remote attacker to reset user passwords.
The vulnerability is a result of the way WordPress processes password reset requests. An attacker can send a spoofed HTTP request while initiating the reset process in order to be sent the new password code.
Return To Article