{"id":13751039,"date":"2020-12-06T14:10:43","date_gmt":"2020-12-06T14:10:43","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/security-issue-with-debug-log\/"},"modified":"2020-12-06T14:10:43","modified_gmt":"2020-12-06T14:10:43","slug":"security-issue-with-debug-log","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/security-issue-with-debug-log\/","title":{"rendered":"Security Issue with debug log"},"content":{"rendered":"<p>I&#8217;ve just found a hacker using the easy smtp debug log as part of a scheme to reset the admin password on one of my sites. How do I contact the developer to ask them to update an .htaccess file to prevent this from happening? Luckily I had 2FA switched on to prevent them from getting any further.<\/p>\n<p>I&#8217;ve fixed my own site, but something tells me that these attacks are not random and other users might be affected.<\/p>\n<p>Graeme<\/p>\n","protected":false},"template":"","class_list":["post-13751039","topic","type-topic","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/13751039","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/13751039\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=13751039"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}