Wordpress Vulnerable (2.3.1 and below)

It has been reported that the latest version of Wordpress is still vulnerable to abuse.

Jaimie Sirovich over at SEO Egg Head today reported that on returning from holiday he found that his blog had been hit by what he calls a HTML tainting attack.

Jaimie has not gone into detail on how the attack was achieved but he has informed Wordpress of his findings. Jaimie will also be releasing a plugin shortly for Wordpress that will help find if your installation of Wordpress has been affected. Hopefully when he releases the plugin it may shed light on the method used for achieving the attack.

Jaimie has also gone onto suggest who he thinks is responsible for the attacks. For more information please visit SEO Egg HEAD.

UPDATE

Jaimie has released the plugin as promised which can be viewed HERE. Unfortunately the plugin has not given any clues as to how the hack was achieved. The plugin simply searches through the blogs post table for adshelper or softicana. These seem to be the names of the domain names used in the links.

Popularity: 43% [?]

Leave a Reply