Get a Pentest and security assessment of your IT network.

News

WordPress Zero-Day Could Expose Password Reset Emails

Polish security expert Dawid Golunski has discovered a zero-day in the WordPress password reset mechanism that would allow an attacker to obtain the password reset link. The issue, tracked via the CVE-2017-8295 identifier, affects all WordPress versions and is related to how WordPress sites put together password reset emails. An attacker can craft a malicious request that triggers a malicious HTTP request to trigger a tainted password reset operation by injecting a custom SERVER_NAME variable, such as “attacker-domain”””

Source: https://www.bleepingcomputer.com/news/security/wordpress-zero-day-could-expose-password-reset-emails/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Vulnerabilities In Alibaba threatens security of million users

News

Russian cybercriminal Roman Seleznev gets another prison sentence