WordPress Warning - Vulnerabilities

Interconnect IT

Free Member
Nov 15, 2007
1,229
192
Liverpool
Various dangerous vulnerabilities have appeared in WordPress.

If possible, you should upgrade as soon as possible to the latest version 2.3.3

If not, and remote or mobile posting isn't used, then delete or totally rename you xmlrpc.php file in the root of your WordPress installation - that'll deal with the worst of the nasties.

The range of WP hack attacks is at an all time high - a sign of their success. I hope they get on top of these things sooner rather than later. Upgrade paths should be easier in v2.5.

Posted here because I know a lot of you here are using WordPress as a website platform or blog.
 
Out of curiosity, what version was your friend running?

Touch wood we've never been hacked. Plenty of attempts though! I remember when lots of subscribers were registering on my site. They didn't get any further but it spooked me. Mostly came from Russia that one. Our biggest target is going to be Sniff Petrol - lots of traffic when he's updating it.
 
Upvote 0
Not sure, to be honest I didn't check. At a guess the last version was 2.1

But for the last few weeks a few weird things have been happening. It sounds like someone has been able to either access the admin panel or alter parts of the site remotely. Sorry to be vague I really don't know the ins and outs of what has happened.
 
Upvote 0
0 Blogs Hacked
2 Blogs under DoS due to the issues in versions < 2.2

Just what we need, most of the time its due to a lack of attention to updates.

All though it now means i need to update our Wordpress Application Pack for our control panel, happy days :(
 
Upvote 0
It's a pain. Hopefully the WordPress team, with its new funding, will be able to spend some more time on security now.

The biggest problem is that it's inherently unsound thanks to the plugins situation IMO. So they either need to make upgrades and plugin upgrades simpler, or they need to look at other ways to fix things.

But you know, I never heard anyone say they chose WordPress because the security was so darned strong :)
 
Upvote 0
Something weird happened to my site today.

All the other pages & posts apart from the index were throwing up a 404 error. I had to go into each one, edit it and just save it again. Now they're all back.

Bit odd.
 
Upvote 0
It's too late to be sure now, but I wonder if it was caused by an .htaccess problem/permalinks? Index page wouldn't be affected by that because it's accessed slightly differently.
 
Upvote 0
Made me laugh! :)
Why? :|

Sadly widely used open source software such as WP, osCommerce, phpBB, etc will come under heavier attack as hackers know they are in such widespread use (because they are free) and do not have the same commercial controls placed on their security.

Saying that, there are a lot of commercial products out there that could learn a lot from the OS community ;)
 
Upvote 0
Ah.

Now this COULD have something to do with me playing around with a htaccess file as per Matt Cutts advice I posted above.

...and by could, I mean definitely. :redface:
 
Upvote 0

Latest Articles