Wordpress Vulnerability in Version 2.8.3 or Older Allows the Creation of Hidden Admin Accounts

GoldSparrow By GoldSparrow in Computer Security | 0 views
Rate it:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...

Wordpress Vulnerability Fire
If you are a Wordpress user running version 2.8.3 or older, then you simply CANNOT ignore this. Malware and Spam may soon bombard your system if you do not update immediately. A worm, which has been discovered by Wordpress, has already been fixed in the version 2.8.4 security release.

A newly discovered Wordpress security exploit or worm has the ability to take full control of a website running Wordpress by making itself an administrator account. The vulnerability allows an attacker to start posting malware and spam to the website while also being able to disable any anti-spyware plug-ins. The new administrator user can be very difficult to detect as it uses Javascript to work undetected.

Wordpress is the most widely used blogging software available. With thousands of users, Wordpress is essential that webmasters and bloggers be notified of this issue and update to the latest release of Wordpress immediately.

If you have been affected by the recent Wordpress vulnerability, you will notice two clues which indicate your WordPress site has been infiltrated. There will be odd additions to the permalinks and the second clue will be that the virus or “hidden administrator” created a “back door”. It is important to check your site for users named “Administrator 2″ or other suspicious names.

For this problem, Journey Etc. has a possible solution and if you want to prevent your site from being targeted you will need to get the upgrade. To upgrade Wordpress in one simple click, you should look at the InstantUpgrade plugin.

Ultimately, using the latest version or Wordpress will help you stay secure from these viruses in the future but it is also important to ensure that your password can not easily be figured out. To ensure that you are using a strong password, you should visit “How Strong Is Your Password” and discover if your password is one that can be easily compromised.

Also follow @wordpress on Twitter to stay informed about the latest Wordpress upgrades.

Do you blog and use Wordpress as your choice of blogging software? If so, what version are you running? Do you use a “strong” password for your administrative login?

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Digg
  • del.icio.us
  • Furl
  • StumbleUpon
  • Technorati
  • YahooMyWeb
This entry was posted on 08/12/09 and is filed under Computer Security. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Comment

Note: Abusive comments are not allowed. Please do not post comments regarding technical support issues. ESG customers that have issues with SpyHunter should open a customer support ticket.

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Poll

How much money have you spent trying to rid your PC of spyware?
View Results
Follow Us on Twitter

Archives

Home Sitemap RSS Feed Privacy Policy End User License Agreement Copyright 2003-2010. Enigma Software Group USA, LLC. All Rights Reserved.