Shhhh!!!! WordPress, Don’t Shout About your Break-in Then

Just in case you missed it, because I did, WordPress.org had a security breech this week. Several plugins were updated by a hacker (or hackers) who installed backdoor exploits into AddThis, WPTouch and W3 Total Cache that may have compromised self-hosted WordPress websites.

The official statement posted by Matt Mullenweg (founding developer of WordPress) at wordpress.org on the 21st July, explains:

“Earlier today the WordPress team noticed suspicious commits to several popular plugins (AddThis, WPtouch, and W3 Total Cache) containing cleverly disguised backdoors. We determined the commits were not from the authors, rolled them back, pushed updates to the plugins, and shut down access to the plugin repository while we looked for anything else unsavory…”

The announcement was also accessible from the dashboards of millions of WordPress websites under the very inspiring-to-click title of “Passwords Reset”. Unbelievable way to alert WordPress users to the attack, I know, but here’s your screenshot of proof:

WordPress Security Breech

Powerfully Inspiring People to Click..... Not!

Current advice is for anyone who updated any of the compromised plugins up to a few days prior to the 21st of July to immediately update them to their rolled back versions. As a precautionary measure, all user passwords should be changed (try this plugin) along with the cookie salts in wp-config.php (get new ones here).

To increase the security of WordPress plugin development, WordPress has implemented an email notification system that will advise plugin developers when commits are made to their plugins.

Let’s hope WordPress develops a better early warning system for users of the platform too.

Update

Detailed information about the exploits have been published by independent WordPress developer, Adam Harley, here.

Comments

  1. I have been surfing online more than three hours today, yet I never
    found any interesting article like yours. It is pretty worth enough for
    me.

Leave a Reply

All original content on these pages is fingerprinted and certified by Digiprove
Zynga Suspends FarmVille Gift Sending
FarmVille Tips, Tricks and Cheats: Using an Autoplayer
Loading

Invite Friends to ‘JournalXtra’

Supercharge your web design skills with JournalXtra

Buy me lunch!

I'm a cheap date. Where else can you buy lunch for a couple of dollars?

I accept Bitcoin too!

Categories

Dynamik Website Builder
WPMU DEV - The WordPress Experts
StudioPress Theme of the Month