A Tale of Two Websites
Tuesday, September 8th, 2009In what I hope is my last post (for a while) concerning website security, this is a tale of two websites. I know I have been writing about your website’s security, but this has been a growing issue for the (self-hosted) WordPress community lately. My intention is to make sure our community and friends are properly educated about some simple solutions to better protect themselves.
Website 1: Updated WordPress Version
This website owner updated their version of WordPress. A minor error in the administrative settings allowed a hacker to register as a user. Because the software was up to date, the hacker got no farther than joining as a subscriber. No damage was done, no reinstalling of files was needed, and no major overhauls were warranted.
Website 2: WordPress Was Not Updated
The WordPress admin for the second website did not upgrade their WordPress platform. The same minor error mentioned above allowed the hacker to register as a user. However, since the software was out of date the hacker was then able to change themselves to an administrator. They then added other fake users, hid new admins they created, and changed various settings. They also changed the permalink structure to redirect users to potentially harmful websites. An afternoon’s worth of work was required to completely sanitize the website to make it safe once again.
The Importance
Weeks ago, the WordPress community found a hole in the security and the issue was promptly fixed. Once it was resolved, an update was distributed. In fact, the past two software updates included this security patch. People who had not updated their software recently were exposed to the worm and a lot of website owners have been affected. They felt the affect of not staying on top of their updates. The rest of the community was more protected from the attack.
If you want to read more about the importance of updating your WordPress software, Matt Mullenweg wrote a good article on the WordPress blog.
Please let me know if you have any questions concerning your current version of WordPress or if you are confused about updating your version of WordPress.
Stay safe out there!






