There seems to be a very serious wordpress.com exploit which allows 3rd party sites/domains to gather a hash code which can be used to login to an user's account. Here is how to reproduce,
1. Login to wordpress.com
2. Take a look at this page : http://www.sandaru1.com/wordpress_test.html (This page is just showing the hashcode/url, I'm not saving any hashcodes)
3. Open another browser (in an attacker's case, his/her browser) and paste the URL shown in the page
4. Goto wordpress.com on the new browser and you are logged in
The exploit itself seems to be too simple. Am I missing something here or is this a serious bug?
P.S - I emailed both Automattic support and Matt Mullenweg. I didn't get any response back.