Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

TygrBright

(20,763 posts)
Mon Feb 6, 2017, 02:39 PM Feb 2017

If you have a WordPress Website, PLEASE NOTE: FIX THIS ASAP

>cross-posting in Web & Developers<

The recent 4.7.1 release of WordPress software contained a large hole enabling privilege updating and content injection.

They quietly fixed it with the 4.7.2 release-- 'quietly' because it's so big and so easily-exploitable a hole that anyone with the older version is extremely vulnerable and they were hoping to get as many people updated as possible before doing a public "my bad" that would alert crackers to the fun and easy exploit possibilities.

And, sure enough, as soon as the word got out, thousands of sites that hadn't updated were targeted with varying levels of nastiness.

So please, if you have a WordPress site, check to see you are running 4.7.2, and if you find you have the older version, first check to see if you've been hacked: the clue is usually replacement titles on your posts, sometimes they are also redirect links so DO NOT CLICK on any weird-looking titles. Go to WordPress help forums and find this handy guide: https://codex.wordpress.org/FAQ_My_site_was_hacked

Work it through, and then restore from an older content backup, if you have to.

If you haven't been hacked, update to 4.7.2 immediately and thank your lucky stars.

helpfully,
Bright

2 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
If you have a WordPress Website, PLEASE NOTE: FIX THIS ASAP (Original Post) TygrBright Feb 2017 OP
Thanks for the warning! My site had already updated but it's good to check anyway. csziggy Feb 2017 #1
Welcome to 4.7.3 Sentath Mar 2017 #2

csziggy

(34,136 posts)
1. Thanks for the warning! My site had already updated but it's good to check anyway.
Tue Feb 7, 2017, 01:55 AM
Feb 2017

Some time ago I set my WordPress blog to automatically update. It sends me notices when it does so I can check on updates for the plugins.

Latest Discussions»Help & Search»Computer Help and Support»If you have a WordPress W...