It’s possible for a malicious user reset admin password on latest version Wordpress 2.8.3. Check out explanation here, patch here and exploit here.
Wordpress fixes latest security problems, download it now.
Wordpress 2.8.2 is out and covers/patches some XSS problems in comments at admin section.
Wordpress update is out, download here.
Recent Comments