A security bug in the WordPress plugin WP-Slimstat could be exploited by attackers to discover a secret key and use it to run blind SQL Injections. The security issue was discovered by Marc-Alexandre Montpas, a researcher with the firm Sucuri, during a routine audit. If an attacker is able to guess the key could run a series of blind SQL injection attacks and access data contained in the database of the WordPress instance, including user credentials, hashed passwords and WordPress Secret Keys.”]
Source: http://securityaffairs.co/wordpress/34144/hacking/1-million-wordpress-websites-vulnerable.html

