Archive for the ‘Advisories’ Category
Monday, February 22nd, 2010
Thomas Mackenzie has reported a vulnerability affecting Wordpress >= 2.9. Versions before 2.9 are not vulnerable.
tmacuk quote:
Since version 2.9 a new feature was implemented so that users were able to retrieve posts that they may have deleted by accident. This new feature was labelled ‘trash’. Any posts that are placed within the trash are only viewable [...]

Posted in Advisories, BuddyPress Hosting, BuddyPress Plugins, BuddyPress Themes, Gravatar, PollDaddy, WordPress, WordPress Hosting, WordPress MU Hosting, WordPress MU Plugins, WordPress MU Themes, WordPress Video, Wordpress Mu, bbPress, buddypress, wordpress plugins, wordpress themes | No Comments »
Tuesday, January 12th, 2010
If you are running WordPress < 2.8.5 and finding your blog inaccessible at times this post may be for you.
A denial of vulnerability was released back in Oct 2009 that affects < WordPress 2.8.5.
The exploit sends a continuous stream of POST requests with overly large blog titles to wp-trackback.php. This could result in the [...]

Posted in Advisories, BuddyPress Hosting, BuddyPress Plugins, BuddyPress Themes, Gravatar, PollDaddy, WordPress, WordPress Hosting, WordPress MU Hosting, WordPress MU Plugins, WordPress MU Themes, WordPress Video, Wordpress Mu, bbPress, buddypress, wordpress plugins, wordpress themes | No Comments »
Tuesday, December 8th, 2009
One of The Internet Storm Center readers recently discovered a malicious WordPress hacking script.
The script is nothing more then a password guessing tool. However, what makes it unique — as pointed out by ISC, is the fact that it uses a MySQL database backend to store password attempts. This means the script could be executed [...]

Posted in Advisories, Articles, BuddyPress Hosting, BuddyPress Plugins, BuddyPress Themes, Gravatar, PollDaddy, WordPress, WordPress Hosting, WordPress MU Hosting, WordPress MU Plugins, WordPress MU Themes, WordPress Video, Wordpress Mu, bbPress, buddypress, wordpress plugins, wordpress themes | No Comments »
Tuesday, August 11th, 2009
An exploit has been released for all current versions of WordPress including WordPress

Posted in Advisories, BuddyPress Hosting, BuddyPress Plugins, BuddyPress Themes, Gravatar, PollDaddy, WordPress, WordPress Hosting, WordPress MU Hosting, WordPress MU Plugins, WordPress MU Themes, WordPress Video, Wordpress Mu, bbPress, buddypress, wordpress plugins, wordpress themes | No Comments »
Tuesday, August 4th, 2009
If you haven’t already done so, we’d stongly recommend upgrading to WordPress 2.8.3. Also, the WordPress 2.0.x branches are now deprecated (a bit earlier then expected) and will therefore no longer be maintained. [Link]
Unfortunately, I missed some places when fixing the privilege escalation issues for 2.8.1. Luckily, the entire WordPress community has our backs. [...]

Posted in Advisories, BuddyPress Hosting, BuddyPress Plugins, BuddyPress Themes, Gravatar, PollDaddy, WordPress, WordPress Hosting, WordPress MU Hosting, WordPress MU Plugins, WordPress MU Themes, WordPress Video, Wordpress Mu, bbPress, buddypress, wordpress plugins, wordpress themes | No Comments »
Wednesday, July 1st, 2009
DM Albums™ is an inline photo album/gallery plugin that displays high quality images and thumbnails perfectly sized to your blog.
Two vulnerabilities have been made public:
1. Stack released a “remote file disclosure vulnerability” (Low-Medium Risk Level)
2. Septemb0x released a “remote file include vulnerability” (Critical Risk Level)
An attacker could use these vulnerabilities to potentially gain full access [...]

Posted in Advisories, BuddyPress Hosting, BuddyPress Plugins, BuddyPress Themes, Gravatar, PollDaddy, WordPress, WordPress Hosting, WordPress MU Hosting, WordPress MU Plugins, WordPress MU Themes, WordPress Video, Wordpress Mu, bbPress, buddypress, wordpress plugins, wordpress themes | No Comments »
Wednesday, July 1st, 2009
A critical vulnerability has been discovered in the WordPress Plugin Related Sites plugin. An exploit is available in the wild and available on Milw0rm, making this attack easier to exploit.
Although, the vulnerability says that version 2.1 is vulnerable. You should assume previous versions are vulnerable as well.
BlogSec have confirmed that the current version (at the [...]

Posted in Advisories, BuddyPress Hosting, BuddyPress Plugins, BuddyPress Themes, Gravatar, PollDaddy, WordPress, WordPress Hosting, WordPress MU Hosting, WordPress MU Plugins, WordPress MU Themes, WordPress Video, Wordpress Mu, bbPress, buddypress, wordpress plugins, wordpress themes | No Comments »