Quick Online Tips
Home     About     Popular     Cool     Blogging     Downloads     How-to     WP-Themes     Contact

WordPress 2.3.3 Urgent Security Release for XML-RPC Flaw

February 5th, 2008
ADVERTISEMENTS

An urgent wordpress security release is out and its time to upgrade to Wordpress 2.3.3 again. This time its a flaw in XML-RPC implementation that could let people exploit your blog in malicious ways.

The Wordpress team announced that they have found a flaw in XML-RPC implementation such that a specially crafted request would allow any valid user to edit posts of any other user on that blog. Now that is really scary.

Wordpress 2.3.3 also fixed a few minor bugs. They say if you are interested only in the security fix, download wordpress 2.3.3. and after extracting the package, find the xmlrpc.php file in the root directory and copy it over your existing xmlrpc.php. That’s the fastest way to fix the security problem without a full wordpress installation.

They also point to a vulnerability in the WP-Forum plugin that is being actively exploited and if you are using this plugin, remove it until an update is available.

Update – Once you only update xmlrpc.php, the wordpress alert keeps on bothering you repeatedly.

Wordpress Update

So I went around finding files which were updated since the last release. You can simply replace the changed files instead of a full install and stop the message.

xmlrpc.php
wp-admin/install-helper.php
wp-includes/version.php
wp-includes/gettext.php
wp-includes/pluggable.php

Liked it? Subscribe feed and keep reading our latest articles for free.
Share:  Digg   Delicious   Stumbleupon   Twitter   Email to friend

Related Posts

  1. Fix WordPress 2.5 Bugs with 2.5.1 Security Release
  2. bbPress 0.9.0.2 Security Release
  3. Wordpress 2.0.2 Security Update
  4. WordPress 2.4 Skips Release: WordPress 2.5 Next
  5. Wordpress 2.2.1 Release Candidate Available



2 Responses to “WordPress 2.3.3 Urgent Security Release for XML-RPC Flaw”

  1. Blogging Mix says:

    Hey, thanks for the heads up. I’ve just updated my xmlrpc.php file. Hope that’ll do. Cheers :)

  2. Ravi says:

    thanks a lot for pointing out the files pal..

Leave a Reply

writeWrite a guest article - Showcase your site to our active community of bloggers, technology experts, geeks and internet marketers. Read guest articles

Site Hosted by KnownHost.

Fully managed VPS Hosting