If you have a blog running WordPress and hosted on WordPress.com, you should be extra careful when logging into your website's admin panel. What do we mean? When logging into WordPress, don't use public Wi-Fi, as you could be handing over your credentials to a malicious user. Your account can be hacked, even if you have two-factor authentication enabled.

Yan Zhu, a security researcher from the Electronic Frontier Foundation (EFF), observed that blogs hosted on WordPress.com send user identity cookies in plain text rather than encrypted. Thus, even a script kiddie can intercept the login information.
When WordPress users log in to their account, WordPress.com servers distribute a cookie named “wordpress_logged_in” to the users’ browser, as Yan Zhu reports on her blog. The researcher observed that this authentication cookie is sent over HTTP, in a very insecure manner.
[tweet_embed id=471186304667881472]
Someone malicious user can easily hijack HTTP cookies if using the same Wi‑Fi network, using some specialized tools, such as Firesheep, a network sniffing tool. The cookie can be added to any other web browser and will give the hacker illegal access to the victim's WordPress account.
The good news is that, if you have a WordPress site hosted on a server that supports HTTPS, then your blog is not vulnerable to the cookie reuse flaw.
