Wordpress 2.5 is out, upgrade today!
Monday, March 31st, 2008The latest version of Wordpress is only a few days old when I noticed this urgent post in the TrendLabs blog regarding the old version of Wordpress (version 2.3.3 that is). It’s always important to upgrade your software, and this time it can really hurt your visitors and subscribers if you don’t
This javascript injection is createing a directory called 1 in your wp-content directory. So to find out if your blog has been hijacked you should search for a directory called that. This directory will be full of infected files containing links to other infected files
so you need to remove them all if your blog has been infected.
If you blog gets infected, then all your blog pages will be filled with links to other infected pages.
TrendLabs is giving this advice to blog owners:
As of this writing, a fix for this vulnerability has yet to be issued by WordPress. (You may, however, find this and this sites useful.) As a workaround, users may want to close their registration feature. Also, be wary of third-party plug-ins you install in your blog sites.
Popularity: 29% [?]






