September 09, 2009

Wordpress 2.8.4 Fixes A Big Security Hole

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
back to blog index

Time to upgrade your Wordpress sites. A vulnerability in versions prior to 2.8.4 could let the bad guys reset passwords. This particular problem might only be a nuisance since it doesn't necessarily let someone commandeer your user account.

But, there's a nasty worm infiltrating sites based on an older vulnerability in the code. So if you're running an older version of Wordpress - something prior to version 2.8.3 - then you might find your site has been taken over.

The worm takes advantage of a problem with the "permalink structure" (URL rewriting technology) used by Wordpress to infiltrate the system. It can then gain admin-level access to the blog and begin taking other actions, such as modifying post content, adding new comments, and so on.

Cleaning up after the worm isn't exactly simple in all cases either. It's much easier to keep the software up to date to avoid these kinds of problems.

You can get the latest Wordpress code at the site's download page.

End of Article



Windows IT Pro Community
Blogs






Search Security Matters
 
Security Matters
NOVEMBER 2009
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30      
or

 Recently in Security Matters
Wordpress 2.8.4 Fixes A Big Security Hole
Make a Comment
Microsoft Releases 5 Critical Patches
Make a Comment
How To Help Secure HTTP Data Without SSL

Last Comment
The article has very less information. Need some elaboration....
(1 Comments)
Sometimes The Cookie Doesn't Crumble
Make a Comment
SecureTweets for Twitter
Make a Comment

More blogs about technology,
software, and Windows.

SQL Server Magazine Office & SharePoint Pro DevProConnections asp.netPRO ITTV
IT Library Technology Resource Directory Connected Home Windows SuperSite
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc.     Terms of Use | Privacy Statement