Update: OneUtah/WordPress Technical Problems
I’ll upgrade today. If you need a new password, let me know.
With open registration enabled, it is possible in WordPress versions 2.6.1 and earlier to craft a username such that it will allow resetting another user’s password to a randomly generated password. The randomly generated password is not disclosed to the attacker, so this problem by itself is annoying but not a security exploit.
Cliff Lyon
September 14th, 2008 at 9:22 am
Are you going to splurge and spend the extra 7 bucks a month?