WordPress at Risk from Insecure Cookies? | Internet News

WordPress at Risk from Insecure Cookies?

May 28, 2014
1 minute read

From a WordPress perspective, a number of things can be done to improve security as it relates to cookies.

In an email to eWEEK, open-source WordPress developer Andrew Nacin explained that WordPress segregates its cookies for security.

“The front-end cookie is delivered over HTTP by default and is simply used to identify the user for the purposes of the logged-in toolbar, an edit post link in the theme, etc,” Nacin said. “The admin-only cookie is delivered with the secure flag if the user is forcing the dashboard to be used over SSL.”

The admin-only cookie is required to access the dashboard and change settings, manage posts or edit the user’s profile, Nacin said.

Read the full story at eWEEK:
WordPress Gets Flagged for Insecure Cookie Risk

Sean Michael Kerner is a senior editor at InternetNews.com. Follow him on Twitter @TechJournalist.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.