Since version 5.5 of the content management system (cms) wordpress is possible to activate automatic updates not only for the cms itself, but also for plugins. Normally this is an optional configuration. In the case of the popular plugins loginizer, however, the wordpress team made an exception to the wordpress team: from safety reasons, she pushed loginizer 1.6.4 as compulsory updates to wp installations in which the plugin is installed. Admins potentially affected sites should nevertheless check whether the update has arrived at them.
Actually, the plugin loginizer, which is active in more than one million wp installations, has the task of protecting them from unauthorized login attempts. Among other things, it should ward off before brute force attacks by monitoring login experiments over certain ip addresses and blocking access when reaching a maximum access number. In the current case, however, a danger sql-injection bug in loginizer versions before 1.6.4 the complete login protection. An attacker had signed up without valid access data and thus can compromise the complete installation.