WordPress vulnerable to Cross-Site Request Forgery in Connection Information Not yet fixed with the last Update. CSRF issue has been found in Summer of Pwnage hack event which held between July 1-29. This weakness can be utilized to overwrite the FTP or SSH association settings of the infected WordPress site. An assailant can utilize this issue to trap an Administrator into signing into the attackers FTP or. SSH server, revealing his/her login credentials to the attacker. This issue exists in the method request_filesystem_credentials().”]

