Tuesday, January 2nd, 2007...1:47 pm...by: Anthony

WordPress Vulnerability

Jump to Comments

I was reading Reaper-X’s blog yesterday when I came across the post about the latest WordPress vulnerability. Naturally, since we use WordPress, my ears perked up.

As it stands, here is a description of the problem from the SecurityFocus web site:

Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.

Shout out to Reaper-X for bringing this to our attention. We fixed our blog code last night after reading the post :). Today, I noticed that Secunia has also posted on it.

If you use WordPress, here is a link to the official fix that will show you what to change in the code of your templates.php file.

    EDIT: Madhur pointed out that WordPress has not verified this vulnerability. So, keep that in mind when considering the fix (Thanks, Madhur ;)).

Share and Enjoy:
  • Digg
  • del.icio.us
  • Google
  • Facebook
  • SphereIt
  • Reddit
  • Technorati
  • LinkedIn
  • Netvouz
  • description
  • ThisNext
  • MisterWong
  • Wists
  • BlogMemes
  • Furl
  • NewsVine
  • Slashdot
  • Spurl
  1. WordPress Vulnerability There is an unspecified flaw in WordPress that could result...
  2. WordPress 2.0.6 Bug WordPress made the recommendation to upgrade to version 2.0.6 due...
  3. WordPress Keyboard Shortcuts If you use WordPress for your blogging software of choice,...
  4. Lite Post Ok, here is a post of some blog nuggets that...
  5. Minimize Your Blog’s Duplicate Content Duplicate content on blogs is usually a big issue if...

Here are a Few Related Posts

3 Comments

  • Hi man …offcially this has not been confirmed by Wordpress …so better wait for them to confirm ..

  • I agree, but Secunia is usually on top of things and I figured it was better to give everyone a “heads-up” since it is potentially a serious flaw.

    But you are absolutely right, it is best to wait for confirmation :). I am going to edit the post to mention that. Thanks :).

  • Hi! Why I can’t fill my info in profile? Can somebody help me?
    My login is Kisakookoo!

Leave a Reply