Wordpress Unauthorized Comment Disclosure

June 1, 2007 News | Comments (0) admin @ 7:05 am

By Enumerating, the name and email address of a comment author, an attacker can read the comment submitted by the author while the comment still waits an administrator to approve it and publish it. This again points to the need for a better session management in Wordpress. Read the full story here