Tag: cookies

  • WordPress.com Security Vulnerability Stirs Debate Over Responsible Disclosure

    WordPress.com Security Vulnerability Stirs Debate Over Responsible Disclosure

    Late last week, Yan Zhu, a Staff Technologist for the Electronic Frontier Foundation publicly disclosed a security vulnerability she discovered with WordPress.com and how it handles cookies. More specifically, she discovered the “wordpress_logged_in” cookie being sent in the clear to a WordPress authentication endpoint. She was able to use the authenticated cookie to publish blog…

  • WordPress Plugin Authors: Be Up Front and Honest With Users About Tracking

    Plugins collecting information and phoning home to a third-party without the user’s consent is a serious issue in the WordPress community. The WordPress plugin repository guidelines are clear on this matter specifically, point number seven and its sub points. Pooria Asteraky has published a post that explains why there needs to be more transparency across…