Comment Security Hole
-
I discovered a security hole via someone else’s site in the native comment moderation system. If I use the screen-name “whatever” and post and the comment successfully is released to post by an admin, someone else can come along and use the same screen-name to post as though they were me regardless of whether the email address is different. That post by the clone poster then successfully posts to the site without having to go through moderation even if the email WAS different.
So far I’ve only experienced this on one WordPress site, but I should think it would be easily reproducible on most WP sites if I’m correct about this hole.
Viewing 3 replies - 1 through 3 (of 3 total)
Viewing 3 replies - 1 through 3 (of 3 total)
- The topic ‘Comment Security Hole’ is closed to new replies.