An attacker, who is able to register a specially crafted username on a WordPress 2.5 installation, is able to generate authentication cookies for other chosen accounts. This is not good.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/65753/wordpress-cookie-integrity.txt
Source: https://packetstormsecurity.com/files/65753/wordpress-cookie-integrity.txt.html

