Sep 05, 2009 ~ Lisa Sabin-Wilson

[UPDATED] Early versions of WordPress under attack – upgrade to 2.8.4 today!

To all our clients (and anyone else who happens upon this post) who are running the WordPress software on their website: Upgrade now to the latest version 2.8.4. There appears to be a current and ongoing attack against older versions of WordPress. It could be a looooooooooooong weekend for us!

As we read on Mashable:

The warning comes from Lorelle on WordPress after it was discovered that a nasty attack is exploiting security holes in previous versions of the blogging software, creating a new “hidden” Administrator account and getting right down to the database level. These attacks are said to be “growing by the hour”. Lorelle writes:

There are two clues that your WordPress site has been attacked.

There are strange additions to the pretty permalinks, such as example.com/category/post-title/%&(%7B$%7Beval(base64_decode($_SERVER%5BHTTP_REFERER%5D))%7D%7D|.+)&%/. The keywords are “eval” and “base64_decode.”

The second clue is that a “back door” was created by a “hidden” Administrator. Check your site users for “Administrator (2)” or a name you do not recognize. You will probably be unable to access that account.

We are strongly encouraging our clients to upgrade their version of WordPress to make sure you are using the latest version of 2.8.4.  If you don’t know what version you are currently using, login to your WordPress dashboard and if you are running an older version of WordPress, you’ll see a notice at the top that looks like this:

Upgrade to WordPress 2.8.4

Click the “Please update now” link to begin the upgrade process.

For any of you that are using really old versions of WordPress (versions 2.5 and lower) a manual upgrade will need to be done.  Instructions on manually upgrading your WordPress site using FTP can be found in the WordPress Codex here: WordPress Upgrade Extended.  If you need assistance with your manual upgrade – you can contact us for help/support by submitting a ticket in our Help Center.

For anyone who may have already experienced the attack – it’s going to be long Labor Day weekend for you, too!  You will need to export your all your content with the built-in WordPress export, uninstall and reinstall WordPress and re-import the content. It’s a nasty attack that goes all the way into the database, so exporting the database will result in exporting the hacked code too.

In short:  for those who have not yet been affected: upgrade to 2.8.4.  For those who have been, follow the instructions above to fix your site (you can contact us if you are a hosting client of ours)

For those who are already running 2.8.4 – Horray! Enjoy your Labor Day weekend!

[UPDATE] - Check out a great post by the WordPress.Org team on how to keep your WordPress secure – - a stick in time, saves nine (A/K/A/ – always upgrade your WordPress installation with the latest version)

Related Posts:

Leave a Reply

About Us

Blogs About has been in the business of hosting websites and blogs since 2002. We strive to provide quality and affordable hosting packages that are sure to meet your needs! We understand that not everyone is a ‘guru’ at this website stuff – - so we’re here to help you! Through our video tutorials to support help desk, as well as high-end website and blog design services – we cover it all from A to Z, and all points in between! Read what our clients have to say »

Our co-owner, Lisa Sabin-Wilson is also the talent and brains behind the insanely popular and accomplished E.Webscapes Design Studio. And guess what? Clients who host their site and/or blogs with Blogs About Hosting receive a full 10% discount on design services with E.Webscapes. They are truly experts in custom WordPress design, blog design and website designs using different platforms, as well!

We are experts in the use of the WordPress platform! How can we say that? Lisa Sabin-Wilson literally wrote the book on WordPress, she is the author of the official WordPress For Dummies book. Who better to host your WordPress blog than with one of the people who wrote the book on the program! All of our support techs are experts in WordPress, and several other blogging platforms – such as Movable Type and Expression Engine. Sign up today »

Contact Us

Your Name (required)

Your Email (required)

Your Website

Your Subject (required)

Your Message

10+2=?