Update: OneUtah/WordPress Technical Problems

I’ll upgrade today. If you need a new password, let me know.

With open registration enabled, it is possible in WordPress versions 2.6.1 and earlier to craft a username such that it will allow resetting another user’s password to a randomly generated password. The randomly generated password is not disclosed to the attacker, so this problem by itself is annoying but not a security exploit.

One Response to “Update: OneUtah/WordPress Technical Problems”

  1. Oprahs' Orifice Says:

    Are you going to splurge and spend the extra 7 bucks a month?

Leave a Reply

Quicktags: