WordPress 'wp-login.php' Admin Password Reset Security Bypass Vulnerability

Attackers can exploit this issue via a browser.

The following example URI is available:

http://www.example.com/wp-login.php?action=rp&key[]=

Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.


 

Privacy Statement
Copyright 2010, SecurityFocus