A critical flaw in a WordPress add-on was recently patched, which allows crooks to add a rogue admin account to the site.
Last night when I was moderating some comments on TechPP, I was shocked to see an error page instead of the admin panel dashboard. The error read something like this ...