|
|
Log in / Subscribe / Register

Four-year-old comment security bug affects 86 percent of WordPress sites (Ars Technica)

Four-year-old comment security bug affects 86 percent of WordPress sites (Ars Technica)

Posted Nov 26, 2014 23:48 UTC (Wed) by iabervon (subscriber, #722)
In reply to: Four-year-old comment security bug affects 86 percent of WordPress sites (Ars Technica) by bmur
Parent article: Four-year-old comment security bug affects 86 percent of WordPress sites (Ars Technica)

Actually, WordPress doesn't have the equivalent of a root account; instead, some users simply have admin privileges while they ordinarily use the site. This hole wouldn't have been possible if you couldn't simultaneously have the ability to read posts and the authorization to do administrative tasks. (Or, rather, it would have been limited to author/editor-type impact.)


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds