Critical Wordpress Update

Filed under Technology on March 2nd, 2007 by Chris Harrison

I’ve been using Wordpress for a while now, and this is the first time I’ve heard of a critical Wordpress exploit… I just upgraded to 2.1.2 and I recommend you read the articles below and upgrade immediately!

Long story short: If you downloaded WordPress 2.1.1 within the past 3-4 days, your files may include a security exploit that was added by a cracker, and you should upgrade all of your files to 2.1.2 immediately.

Tags:

You can leave a comment, or trackback from your own site. RSS 2.0

10 Comments

  1. Posted: 03/02/2007 Time: 7:48 pm
    Gravatar

    I heard it here first. Thanks, bro.

  2. Posted: 03/02/2007 Time: 10:28 pm
    Gravatar

    I heard it here first. Thanks, bro.

  3. Posted: 03/03/2007 Time: 7:21 am
    Gravatar

    del.icio.us and on the Godbit forum.

    Thanks for sharing the two wordpress links. I hadn’t seen the second post about the Emergency Update Notification for WordPress 2.1+.

  4. Posted: 03/03/2007 Time: 10:01 am
    Gravatar

    I’m glad you’re also trying to get the word out about this critical update. I also mentioned it in my RSS feed by del.icio.us and on the Godbit forum.

    Thanks for sharing the two wordpress links. I hadn’t seen the second post about the Emergency Update Notification for WordPress 2.1+.

  5. Posted: 03/03/2007 Time: 10:29 am
    Gravatar

    I saw the links on the WP dashboard… I’m not sure what the exploit was… but I did notice a weird folder in my root site dir last night that was created on 2 Mar 07. Hopefully they’ll release more info on what exactly happened and what could have happened if people didn’t upgrade.

  6. Posted: 03/03/2007 Time: 1:08 pm
    Gravatar

    I saw the links on the WP dashboard… I’m not sure what the exploit was… but I did notice a weird folder in my root site dir last night that was created on 2 Mar 07. Hopefully they’ll release more info on what exactly happened and what could have happened if people didn’t upgrade.

  7. Posted: 03/03/2007 Time: 1:38 pm
    Gravatar

    Yeah, I noticed the message on my dashboard late yesterday afternoon. I haven’t checked to see if anything weird is going on with my blog yet, but I hope they post some additional info about the problem. My guess is the Wordpress developers want to wait till people have a chance to update the software before publishing information about the exploit…no need for more people to have the knowledge to hack wordpress.

  8. Posted: 03/03/2007 Time: 4:18 pm
    Gravatar

    Yeah, I noticed the message on my dashboard late yesterday afternoon. I haven’t checked to see if anything weird is going on with my blog yet, but I hope they post some additional info about the problem. My guess is the Wordpress developers want to wait till people have a chance to update the software before publishing information about the exploit…no need for more people to have the knowledge to hack wordpress.

  9. Posted: 03/03/2007 Time: 7:25 pm
    Gravatar

    Yeah…. letting people know what could be exploited could encourage people other than the cracker responsible to exploit the exploit.

  10. Posted: 03/03/2007 Time: 10:04 pm
    Gravatar

    Yeah…. letting people know what could be exploited could encourage people other than the cracker responsible to exploit the exploit.

Leave a Comment:

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>