Wordpress Alert: Weak password-reset tokens
A custom reset flow uses predictable, reusable, or long-lived tokens. Someone who obtains or guesses a token may reset another person's password.
What it looks like
A custom reset flow uses predictable, reusable, or long-lived tokens.
Why it matters
Someone who obtains or guesses a token may reset another person's password.
What to check
Audit reset-token generation, expiry, single use, and storage.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP password reset guidance.
- Categories: WordPress
- Tags: #WordPress Security, #Authentication