[wp-trac] [WordPress Trac] #50007: Using this code find in my client site and using this code any one can login without ID password

WordPress Trac noreply at wordpress.org
Sat Apr 25 15:02:37 UTC 2020


#50007: Using this code find in my client site and using this code any one can
login without ID password
-------------------------------------------------+-------------------------
 Reporter:  piyushmca                            |       Owner:  (none)
     Type:  defect (bug)                         |      Status:  closed
 Priority:  normal                               |   Milestone:
Component:  General                              |     Version:  5.4
 Severity:  normal                               |  Resolution:  invalid
 Keywords:  Login security login-without-ID-     |     Focuses:
  password                                       |
-------------------------------------------------+-------------------------
Changes (by Otto42):

 * status:  assigned => closed
 * resolution:   => invalid
 * milestone:  Awaiting Review =>


Comment:

 Yes, that is malicious code, but it is not part of the WordPress system.

 You should investigate how this code got onto your site in the first
 place, and address that security issue.

 In the meantime, this is not the correct place to discuss this issue, as
 this is the bugtracker for the core software, which this is not part of.

 You can talk about it in the Support Forums, and you should read the help
 article available there:

 https://wordpress.org/support/article/faq-my-site-was-hacked/

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/50007#comment:1>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list