HomeinetCookie vulnerability in Wordpress.com

WordPress.com cookie vulnerability

If you have a blog running WordPress and hosted on WordPress.com, you should be extra careful when logging into your website's admin panel. What do we mean? When logging into WordPress, don't use public Wi-Fi, as you could be handing over your credentials to a malicious user. Your account can be hacked, even if you have two-factor authentication enabled.

hacked wordpress

Yan Zhu, a security researcher from the Electronic Frontier Foundation (EFF), observed that blogs hosted on WordPress.com send user identity cookies in plain text rather than encrypted. Thus, even a script kiddie can intercept the login information.

When WordPress users log in to their account, WordPress.com servers distribute a cookie named “wordpress_logged_in” to the users’ browser, as Yan Zhu reports on her blog. The researcher observed that this authentication cookie is sent over HTTP, in a very insecure manner.

[tweet_embed id=471186304667881472]

Someone malicious user can easily hijack HTTP cookies if using the same Wi‑Fi network, using some specialized tools, such as Firesheep, a network sniffing tool. The cookie can be added to any other web browser and will give the hacker illegal access to the victim's WordPress account.

The good news is that, if you have a WordPress site hosted on a server that supports HTTPS, then your blog is not vulnerable to the cookie reuse flaw.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS