Attention WordPressers

Take it from somebody who lost at least one whole blog entirely from the consequences not upgrading WordPress: Upgrading your installation or patch is essential. So read this from Ian Kallen.

Also what he added by IM yesterday:

  What’s happening is: spammers are taking over blogs, posting link farm links on them, obscuring their human visibility with CSS tricks but the links are still visible to crawlers…
  All wordpress users that haven’t patched or upgraded to v2.3.3 are vulnerable.
  WordPress does not auto-update security fixes.
  …Any help you can provide getting the word out would be a mitzvah

I added the last link. 🙂

This entry was posted in Blogging, problems. Bookmark the permalink.

24 Responses to Attention WordPressers

  1. PXLated says:

    That’s one reason I stay away from WordPress, too many security problems and updating is a royal pain if you use a lot of plugins, etc.
    See here – http://secunia.com/search/?search=Wordpress&w=0

  2. Note that if you don’t want to do the whole upgrade rigamarole and want to fix the problem fast, you can download and replace only the xmlrpc.php file. I’ve done it on several WP blogs and none have been compromised:

    http://wordpress.org/development/2008/02/wordpress-233/

  3. dave says:

    you will really love 2.5 when it’s ready, though you can likely upgrade to the RC now…admin totally improved, security enhanced further..

  4. rob friedman says:

    With the new WordPress 2.5 RC’s there is a new automatic plugin upgrade feature, making plugin upgrades simple.
    The only hard part is upgrading the WordPress itself, but even that is trivial if you use the subversion method.

    When 2.5 goes final it should be interesting.

  5. Doug says:

    There is also the auto upgrade plugin which makes life easy, http://wordpress.org/extend/plugins/wordpress-automatic-upgrade/

  6. REBLogGirl says:

    I have to agree with PXLated. WP is just too insecure. Matt and his crew just write bad code and bod code leads to one thing… security issues. I’m sure there are still security holes in the new version as well having seen enough of their code in the past- remember this is the same guy that thinks PHP5 is BAD and IRRELEVANT.

  7. i upgraded to the latest version just a week ago.

    Thanks for the info

  8. Doc Searls says:

    REBLogGirl, are Matt & crew the only ones writing WordPress? Last I looked it was an open source project.

  9. kyle says:

    I’m confused. Does this apply to wordpress blogs installed on a separate domain, or hosted on wordpress.com, or both? Thanks.

  10. Kyle, This only applies for wordpress blogs installed on a separate domains.

    FYI, all new version of WordPress 2.5 has been released containing many new features.

  11. Thanks for the clarification between separate domains and wordpress.com hosted.

  12. robin Sing says:

    I have been afraid to upgrade but after reading this I guess it’s really nothing to worry about.

  13. I understand that it is open source and I also understand REBloggirl’s point, ..but can’t there be a concerted effort to close the bad links in the chain?

  14. Barry,
    I would think that it would be to the best of everyone to close off the bad links in the chain. I feel upgrading wordpress initially is just like a new Windows SP.

  15. John Sabia says:

    Glad I stumbled here – I have not upgraded but will do so now.

  16. That was a great post, I really enjoyed it. I will have to bookmark your site so I can come back later.

  17. Mike says:

    It’s also a good idea to backup your blog’s database so that it can be restored in case of getting hacked, a crash, whatever.

  18. Upgrading your WP blog is a simple one button install, but in some instances the accompanying plugins will also require update. It’s always best practice to first backup either internally via WP or through your hosting account (via cpanel for example).

  19. Robin says:

    WordPress just came out with another version. Hopefully this upgrade will make the problems that many have experienced rendered moot.

  20. Lenny says:

    I am finding that WordPress is doing all they can to keep one step ahead of the idiots out there. But of course one should indeed back up regularly especially if you are posting a lot of content. Better safe than sorry for sure.

Leave a Reply

Your email address will not be published. Required fields are marked *