An oversight in a WordPress plug-in exposes PII and authentication data to malicious insiders.

Threatpost