WordPress Security Alert
Security and Fraud March 6th, 2007
I host all of my blogs using the WordPress blogging software, so this warning definitely caught my eye. If you have downloaded WordPress 2.1.1 within the last week or so, your version of the software may include a security exploit that can leave your web server vulnerable. According to the good folks at WordPress, someone had managed to access one of the servers that distributes copies of the WordPress software and added potentially malicious code to the WordPress download files.
While the company doesn’t think that all of the WordPress 2.1.1 download files were effected, they are assuming the worst and shutting down that version of WordPress. They’ve released a new version of WordPress, 2.1.2 that fixes this security exploit. They’ve also taken measures to lock down the affected server and investigate how this all happened. You can read the full security alert at the WordPress site.
If you have downloaded version 2.1.1, you should upgrade to the new version immediately. Also, if you know of anyone who is also running WordPress on their web server you should pass this information along to them.