SpoofedMe

  • Unknown's avatar

    You may already be aware of the IBM report of the SpoofedMe attack used to impersonate a user in order to gain control of their account on vulnerable websites.

    The attack works when a hacker creates a social login account with the victim’s email and logs into a site where the victim already has an account. The site automatically merges the account based on the matching email addresses, granting the hacker access to the victim’s account on that site.

    We’ve found that WordPress authentication is similarly vulnerable. Please take a look.

    The blog I need help with is: (visible only to logged in users)

  • Unknown's avatar
  • The topic ‘SpoofedMe’ is closed to new replies.