This entry was posted on Friday, March 2nd, 2007 at 4:45 PM and is filed under Security, WordPress. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.
I caught wind of this about 20 minutes ago but wanted to upgrade my blog before I posted about it. So, now my WordPress blog is running version 2.1.2 and I should be safe.
From reading the official post about this on the WordPress site, it appears that someone gaines user level access to the wordpress.org server and modified the 2.1.1 release of WordPress. The post states that some PHP code was added to some core WordPress files that would allow remote PHP execution about 3-4 days ago. Not good! However, I am glad that WordPress has made this public and has already corrected the issue and made an uncompromised version of the code available for WordPress users to download and upgrade.
If you’re running WordPress version 2.1.1, UPGRADE NOW!!!
Until next time…


























