scriptygoddess RSS Feed
 
 
 
 

WP security bug

There's a pretty serious security bug with WP 1.2.1 (and the current 1.3 alpha), one that can make it so your blog is basically unusable (not permanently, as far as I can tell) but still - if you're using WordPress you should probably make this change.

In any case, here is how you fix the problem. It's a very easy fix. If you can search for text on a page, you can fix this problem.

I hesitated posting this, because I don't want to "start a panic" - nor do I want to give instructions on how to hack WP blogs. But I do think it's important that people go ahead and make this change.

[brought to my attention by Christine]

5 Responses to “WP security bug”

  1. 1
    Shelagh:

    Thanks for the heads up :)

  2. 2
    Christine:

    If something goes wrong, it can be fixed and usuable again; it requires knowledge of PHPMyAdmin to go into the database to fix the URL. Then everything should work again just fine.

  3. 3
    Mark J:

    This isn't a severe site breach, so I don't have a problem with notifying everyone. If this were a more serious bug, then I'd use caution. But all it really does it make your site ugly and quasi-functional, and there is no loss of data.

  4. 4
    snapping links » assorted:
    [...] the RSS feed for APOD (I've been hoping there was something like that out there.) something more to do really slick screensavers (open source, OpenGL [...]

  5. 5
    marcus' scrappad:
    WordPress bug
    Just saw that scriptygoddess posted about it, too. I first read about the bug in this post, but didn't think much of it. Until three days later my site was broken. I grepped through the log file to see what had happened, and found the guy who did it. …

Bookmarks

WordPress Resources

Meta

Random Stuff