[wp-trac] [WordPress Trac] #11813: Post password stored as plaintext

WordPress Trac wp-trac at lists.automattic.com
Thu Jan 7 18:33:46 UTC 2010


#11813: Post password stored as plaintext
--------------------------+-------------------------------------------------
 Reporter:  ericmann      |       Owner:  ryan          
     Type:  defect (bug)  |      Status:  new           
 Priority:  normal        |   Milestone:  Future Release
Component:  Security      |     Version:  2.9.1         
 Severity:  normal        |    Keywords:  post-password 
--------------------------+-------------------------------------------------
Changes (by scribu):

  * milestone:  Unassigned => Future Release


Comment:

 I see no harm in doing at least a simple md5() on the password. (It
 shouldn't be the same hashing function used for user passwords)

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/11813#comment:1>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list