RocketProfit Affiliate Network: Make More Money Now
 




Get Reviewed by this Blog for only $500
DealDotComTTZ MediaGoogle Adsense
Pepperjam NetworkBidvertiser
Text Link AdsKonterra

Our favorite blogging software, Wordpress, has released an urgent security update that everyone should upgrade to.

If you have registration enabled a flaw was found in the XML-RPC implementation such that a specially crafted request would allow a user to edit posts of other users on that blog. In addition to fixing this security flaw, 2.3.3 fixes a few minor bugs. If you are interested only in the security fix, download the fixed version of xmlrpc.php and copy it over your existing xmlrpc.php. Otherwise, you can get the entire release here.

Also, there is a vulnerability in the WP-Forum plugin that is being actively exploited right now. If you are using this plugin, please remove it until an update is available from its author.

Since we are talking security, remember to use strong passwords and change them regularly. While you’re updating WP and your plugins, consider refreshing your passwords.

The part about changing your passwords often is a good idea. I’m going to update both blog and passwords now.

Find out what I am doing right now by following me on Twitter! If you like this post then please consider subscribing to my full feed RSS. You can also subscribe by Email and have new posts sent directly to your inbox.

Make Money Online with John Chow's Ad Network - Join TTZ Media Now!
1 Star2 Stars3 Stars4 Stars5 Stars (6 votes, average: 1.67 out of 5)
Loading ... Loading ...

Here's A Few More Related Posts

  • I Am Loving Wordpress 2.5
  • Wordpress 2.1.1 Released
  • New Wordpress 2.0.6
  • Wordpress 2.5.1 Available for Download
  • Wordpress 2.1.1 Dangerous, Upgrade Now!

    RSS feed | Trackback URI

    39 Comments »

    Comment by xanete
    2008-02-05 10:50:03
    MyAvatars 0.2

    It sounds interesting. I will try it. ;)

    Comment by Make Money Schemes
    2008-02-05 11:26:26
    MyAvatars 0.2

    This is the first update I’ve applied in a year, that was one serious security risk. I also took the chance to go for a new design whilst I was upgrading.

     
     
    Comment by RacerX
    2008-02-05 11:19:35
    MyAvatars 0.2

    Blogger is so FUBAR right now it is tempting to jump…

    Picture loader doesn’t work after you spell check…which isn’t working!

    Comment by Neil Duckett
    2008-02-05 15:29:38
    MyAvatars 0.2

    You’ll never look back, Wordpress rocks.

     
    Comment by Nicholas James
    2008-02-05 16:26:23
    MyAvatars 0.2

    Wordpress rocks…the best blogging platform on the market at the moment

     
     
    Comment by Syed Balkhi
    2008-02-05 11:40:06
    MyAvatars 0.2

    yes this is a major issue … i am in process of updating Balkhis.

    Comment by Nicholas James
    2008-02-05 16:38:35
    MyAvatars 0.2

    yea you should, its worth the upgrade whenever one is released.

     
     
    2008-02-05 11:49:17
    MyAvatars 0.2

    Wordpress is the best blogging software available - for sure. I also
    love using it as CMS for midsized websites.

     
    Comment by InfectedByBugs
    2008-02-05 11:50:42
    MyAvatars 0.2

    This was sorta stupid of WP to release another update so late. Why didnt they just fix it in the last release which came out about a week ago!

    Comment by Make Money Schemes
    2008-02-05 12:13:16
    MyAvatars 0.2

    Maybe it wasn’t identified then?

     
     
    Comment by Duckeldanny
    2008-02-05 11:58:00
    MyAvatars 0.2

    sure, wordpress is the best blog software ever

     
    Comment by AndrewPavelski
    2008-02-05 12:38:07
    MyAvatars 0.2

    Well, I guess I’ll check it out… :wink:

     
    Comment by Heidi
    2008-02-05 13:13:09
    MyAvatars 0.2

    I will have to make sure to have my hosting company look into this. Thanks for the heads up.

     
    Comment by Start Blogging
    2008-02-05 13:51:13
    MyAvatars 0.2

    Will do. Thanks for the update.

     
    Comment by Robert Afnani
    2008-02-05 14:35:27
    MyAvatars 0.2

    Saw it on my WP dashboard. Updating now!

     
    Comment by Miley Cyrus
    2008-02-05 14:57:34
    MyAvatars 0.2

    Major security update.. yeah I don’t know how people who have 5+ blogs manage these updates because it’s such a hassle. I only have 3 blogs at the moment and I’ve so far postponed this update to next time I’ll have some free time and feel like backing up/ updating.

    By the way, how often do you backup your sites?

     
    Comment by Johan Cyprich
    2008-02-05 15:26:23
    MyAvatars 0.2

    It’s amazing how many critical updates are the result of security concerns in WordPress. WordPress is written in PHP4 and this is not the best choice for secure applications. A rewrite in PHP5 is necessary.

    Comment by Nicholas James
    2008-02-05 16:41:01
    MyAvatars 0.2

    No because PHP5 isn’t universally used yet.

     
     
    Comment by Louis
    2008-02-05 15:59:41
    MyAvatars 0.2

    Well on the other side, PHP5 isn’t as widely used as PHP4 right now, but I’m sure things will evolve over time. I glanced at the Wordpress post about upgrading, and jumped at downloading/updating. When I re-read it, it did say it would allow an existing user to edit other users’s post. So if you had only 1 user, it wasn’t as crucial as initially thought. Always good to upgrade though.

     
    Comment by Nicholas James
    2008-02-05 16:40:01
    MyAvatars 0.2

    Saw it on my dashboard before and upgraded :mrgreen:

     
    Comment by Tyler Cruz Subscribed to comments via email
    2008-02-05 17:10:50
    MyAvatars 0.2

    I believe I was just a victim of this exploit. I was washing dishes when I got a message on my Blackberry stating my blog was down.

    _All_ my posts were deleted… Fortunately, I have an insane amount of backup measures in place, and was able to restore my blog, and then upgrade to 2.3.3.

    So… UPGRADE TO 2.3.3 ASAP. I’m not positive if this was what caused my blog to have all of the posts erased, but I’m thinking it’s a likely reason.

     
    Comment by Penny Raine
    2008-02-05 21:22:44
    MyAvatars 0.2

    And if we don’t have registration enabled is this upgrade still needed? I have customized my theme, is there any danger of losing those customizations when I upgrade?

    Comment by Miley Cyrus
    2008-02-06 05:48:10
    MyAvatars 0.2

    Was wondering the same thing and I came to the conclusion it’s not needed but guess I’ll still upgrade it eventually.

     
     
    Comment by Photoshop Tutorials
    2008-02-06 03:12:07
    MyAvatars 0.2

    thanks for the update, and Penny Raine, no worries, no danger of losing customizations, …… i think. :lol:

     
    Comment by Haroon
    2008-02-06 04:23:25
    MyAvatars 0.2

    ahh already upgraded :wink:

     
    Comment by Katie
    2008-02-06 07:44:02
    MyAvatars 0.2

    Nice post :) I want to get WordPress Someday when I get hosting with a good host other than Blogger. I can’t wait. It will be exciting. :wink:

    ~Katie :razz:

     
    Comment by Mark Heinemann
    2008-02-06 09:35:01
    MyAvatars 0.2

    Yeah, I’m updating today on both my sites. Always, backup!
    Take care,
    Mark :grin:

     
    Comment by Haroon
    2008-02-06 10:20:48
    MyAvatars 0.2

    Tyler - I just want to tell you that your lucky man you had backup. I was not that lucky as you, my other blog was cleaned out and i couldn’t do anything about that. :cry:

     
    2008-02-06 14:47:41
    MyAvatars 0.2

    another update i only just updated to 2.3.2

    i belive with this one you only need to update the xmlrpc.php file

     
    Comment by Fahmishah
    2008-02-06 20:43:05
    MyAvatars 0.2

    i have already update it

     
    2008-02-07 04:00:50
    MyAvatars 0.2

    [...] you password periodically as John Chow has rightly added in his own post. John has provided detail of one major file that prompted the [...]

     
    Comment by Photoshop Tutorials
    2008-02-07 04:22:59
    MyAvatars 0.2

    Some strong tips there about passowrds guys. I forgot to mention before but updating your passwords regularly is the best form of defense, any one can have against hackers!

     
    2008-02-07 04:34:47
    MyAvatars 0.2

    [...] you password periodically as John Chow has rightly added in his own post. John has provided detail of one major file that prompted the [...]

     
    Comment by David Chew
    2008-02-07 10:08:24
    MyAvatars 0.2

    Thanks for the post john. :grin:

     
    Comment by spidro Subscribed to comments via email
    2008-02-07 16:15:40
    MyAvatars 0.2

    thanks for the update , i stared to use wordpress few weeks ago and this is the first update for me

     
    Comment by Feed Flare
    2008-02-08 11:08:37
    MyAvatars 0.2

    Thanks John for the heads up!

     
    Comment by mack goodman Subscribed to comments via email
    2008-02-08 17:19:05
    MyAvatars 0.2

    I just copied the file xmlrpc.php over and that was easy instead of the full update, but I couldn’t get rid of the update notice. BUT I FOUND THE WAY!! :razz: Just get the new version 2.3.3 and locate the “version.php” file and copy that to the wordpress/wp-includes directory and that does it… Thanks John!

     
    Comment by Terra Andersen
    2008-02-08 22:38:33
    MyAvatars 0.2

    Looks like it’s time to update! thanks for the heads up! - I must be living under a rock, because I didnt even hear about this until now.

     
    2008-02-12 09:46:05
    MyAvatars 0.2

    [...] found myself reading Johnchow’s blog about this recent update and he said the following about this update. "If you have [...]

     
    Name (required)
    E-mail (required - never shown publicly)
    URI
    Your Comment (smaller size | larger size)
    You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.