An attacker may be able to take complete control of a website using the WordPress due to the lack of a cryptographically secure pseudorandom number generator (CSPRNG).
A CSPRNG is a mechanism that generates random numbers on a computer, which can be applied for cryptographic purposes, such as generating keys or salts. The numbers are pseudo-random because a truly random sequence can only be generated theoretically.
The WordPress was discovered by Scott Arciszewski, a web developer from Orlando, Florida. He has already informed WordPress engineers about the need to implement a CSPRNG mechanism in the platform, in order to eliminate even the slightest possibility that someone could predict the link used to reset passwords.
Anyone who can do this will be able to hack every WordPress site on the web. However, there is currently no method available.
Arciszewski says he tried to bring the issue to the attention of WordPress engineers several times. The first time was on June 25, 2014, by opening a ticket about the issue on the platform's tracker. The next time was during WordCamp in Orlando, a conference focused on the WordPress platform.
A publication by the researcher that fully discloses the vulnerability also includes a patch created by him, which has not yet been integrated into WordPress.
Patch available with unit tests and PHP 5.2 on Windows support at https://core.trac.wordpress.org/attachment/ticket/28633/28633.3.patch
It should be noted that WordPress is used by 75 million websites on the internet. However, this vulnerability requires a lot of knowledge and skills, which discourages many would-be hackers.
Source: secnews.gr

