StudioPress Community Forums
  StudioPress Community Forums > Forums > General Discussion
For help and support, access to your downloads, or to manage your account please log into My StudioPress.

These forums have been set to read-only so you can browse the existing topics for any questions you may have.

For general discussion on WordPress, CSS and design (NOT for support) visit the new Community Forums.
 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1  
Old 08-18-2011, 11:24 PM
birdonawire55 birdonawire55 is offline
Registered User
Pro Plus Member
 
Join Date: Oct 2008
Posts: 71
Exclamation New Wordpress Vulnerability Affecting Blogs all over

i woke today to a huge nightmare of hundreds of injected wordpress blogs, many of them genesis installs.. Home/front pages were displaying an error and antivirus programs were going crazy. I'm still cleaning blogs now after midnite.. but here's the thing..

this is cross host, cross framework and its pretty simple. apparently its coming through the thumnail regeneration plugin but dropping code into wordpress indexes (all of em) as well as the genesis framework index.php and widgeted footer.php in the child theme. Also if there's a home.php it drops in there.. I'll be glad to provide you with the dropped in code (its crude at best.. not well thought through as there are multiple misspellings etc) and mostly a huge pain in the backside to clean up.. If some code genius has any ideas on how to patch Genesis on this would be great.. however the code gets dropped into every stinkin theme in the blog if they have more than one... I've bellyached to support at dreamhost, bluehost, eleven2, media temple and more and they all swear its not their fault.. so I'm guessin its just a zero day exploit..but sheesh.. consider this my rant.. and warning... If someone needs some help getting this mess out .. holla.
 

Tags
wordpress exploit

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
TimThumb Vulnerability Tombo General Discussion 7 08-16-2011 08:50 AM
XSS Vulnerability in Allure clementsm General Discussion 1 03-11-2010 04:43 AM


All times are GMT -5. The time now is 02:58 AM.

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.