IT Security & Network Security News & Reviews - eWeek




WordPress Ships `Urgent` Security Update




A security hole in the XML-RPC implementation allows unauthorized third parties to edit WordPress-powered blogs.

Blogging software provider WordPress has shipped an "urgent" security update to fix an XML-RPC implementation flaw that allows unauthorized third-party editing of blog posts.

With WordPress 2.3.3, the open-source company patches a bug that could let attackers use specially crafted requests to edit posts of any other user on that blog. An attacker would need valid user credentials to edit posts by another user on the blog, WordPress said in an advisory.

"If you are interested only in the security fix, download the fixed version of xmlrpc.php and copy it over your existing xmlrpc.php [file]," the company said.

The new version of WordPress, which is widely deployed on several high-profile blog networks, is available here. 

Separately, WordPress notified users of a serious—still unpatched—vulnerability in the WP-Forum plug-in that could lead to SQL injection attacks against databases.

The WP-Forum plug-in bug "is being actively exploited right now," the company warned, urging users to remove the vulnerable plug-in until an update is available.

This vulnerability, rated "moderately critical" by Secunia, allows a malicious hacker to "retrieve user names, password hashes and e-mail addresses" for all users on a compromised blog, including administrators.

The WordPress developer team also urged bloggers to use strong passwords on all accounts and to consider changing those passwords regularly.







 
 
>>> More IT Security & Network Security News & Reviews Articles          >>> More By Ryan Naraine
 

FEATURED SPONSOR MESSAGE

Microsoft Sponsored Resource Center

Increase Your Microsoft Office 365 Knowledge! Dig inside this suite of cloud-based collaboration tools.

Watch the video >>

Brought to you by





Advertisement
eWEEK Quick LInks

 
Close this advertisement