Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v9 - Exploits Update (Fri Aug 28 2009)

Wordpress Password Reset Exploit

Exploits/Authentication Weakness  []




• Fri Aug 28 2009
A weakness has been reported in WordPress which can be exploited to bypass certain security restrictions. The weakness is due to a bug within the password reset functionality when verifying the secret key. This can be exploited to reset the password of the first user without a key in the database (usually administrator) without providing the correct secret key.

Exploits Vulnerabiltiy: NOCVE-9999-39525



< Back to Product Updates