Wordpress Alert: Stolen administrator session cookies
An active admin session is reused from another browser or location. The attacker can act as the administrator until the session is revoked.
What it looks like
An active admin session is reused from another browser or location.
Why it matters
The attacker can act as the administrator until the session is revoked.
What to check
Review active sessions and investigate XSS, compromised devices, or exposed cookies.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP session management guidance.
- Categories: WordPress
- Tags: #WordPress Security, #Authentication