Thats what I thought, but on one of my sites where I am the only admin. My account got hacked by spider team yesterday. they were able to change the pass and email using this exploit. Now I don't click on any links nor enter my password in any pop up windows, so they were some how able to exploit this through a shell. I have since renewed my access and upgraded the site from 3.7.3 to 3.8 beta to test it out.
I would recommend upgrading or applying the patch.



LinkBack URL
About LinkBacks






Reply With Quote