The Lair

Do not meddle in the affairs of dragons, for you are crunchy and taste good with ketchup

wordpress 2.1.1 exploitable in the worst way

March 3rd, 2007

Dev blog announcement. Essentially, someone got into the Wordpress install hosted on the servers and made some modifications to a couple of files. Malicious changes at that. The information in the blog post seems to indicate that feed.php and theme.php (both in wp-includes) were modified. Perhaps other files were as well. The changes seem to have been made fairly recently (3-4 days ago?) but best not to take any chances.

So umm. Please go download the latest release (2.1.2) if you are running 2.1.1 - don’t mess around waiting with this one, just go do it now. Upgrade, make sure all the files are overwritten by the latest release.

I also took the liberty of mailing a few people who are running potentially exploitable versions of Wordpress - drop me a reply if you need a hand upgrading or need a few custom access rules to prevent malicious access in the meantime.

And yeah, stuff like this can happen from time to time. It can happen to anyone and to any project. I’m not particularly happy with how long it took before the malicious mod was discovered but better late than never applies, I suppose. Oh and a few hours of combing through logs for a couple of blogs await - I need to see if some nasty cracker exploited the wide open installs on this domain before I had a chance to make the upgrade. Le sigh.