The great minds behind WordPress discovered another vulnerability yesterday: a specially crafted URL could be requested that would allow an attacker to bypass a security check to verify a user requested a password reset. That would mean that the first account without a key in the database (usually the admin account) would have its password [...]
Continue reading about WordPress 2.8.4 – another security release