If you are not running Wordpress 2.8.4, your site is vulnerable!  smbutton-blue Wordpress 2.8.4 has been released to fix huge a security hole.  This is the vulnerability that was discovered:

A specially crafted URL could be requested that would allow an attacker to bypass a security check to verify a user requested a password reset. As a result, the first account without a key in the database (usually the admin account) would have its password reset and a new password would be emailed to the account owner. This doesn’t allow remote access, but it is very annoying. /src

If you’ve been thinking about upgrading but haven’t gotten around to it yet, now would be a really good time.  Wordpress 2.8.4 is highly recommended for all users of Wordpress as this version is a security release which fixes all known problems. Available for download here.

Related Posts with Thumbnails

Related Posts

  1. WordPress 2.9.1 Peeping Bug
  2. Widgetbucks Deletes Publisher Accounts!
  3. Arras Theme – Free Wordpress Theme for 9/08
  4. eBusiness – Wordpress Theme for 5/22
  5. Quadro – Wordpress Theme for 2/10