View Single Post
  #1 (permalink)  
Old 03-03-2007, 03:11 PM
Larwee's Avatar
Larwee Larwee is offline
5 Star Administrator
 
Join Date: Jul 2006
Location: St. Louis, Missouri USA
Posts: 2,824
Arrow WordPress server hacked. Downloads have serious flaw.

All WordPress users who downloaded and installed version 2.1.1 are being told they should upgrade to version 2.1.2. Earlier versions of Wordpress are not affected.

User-level access was gained to one of the wordpress.org servers and the download file was modified.

The compromised code was distributed through the wordpress.org site.

The WordPress developer is saying:
Quote:
If your blog is running 2.1.1, please upgrade immediately and do a full overwrite of your old files, especially those in wp-includes. ... If you are a web host or network administrator, block access to 'theme.php' and 'feed.php', and any query string with 'ix=' or 'iz=' in it.
Here is a link to the complete details on this very important issue http://wordpress.org/development/2007/03/upgrade-212/
Reply With Quote