But as the site A information is leaked on OTHER site B is it really needed that the vulnerable function have to be enabled on site A, or is it perhaps enough having site B had those active?
Just asking, cause e.g. change.org already writes mails telling me to change my password as precaution...