A few words about the RISKS of WordPress 1.2, 1.5, 2.0 or anything less than 2.0.4

Obscurity Through Verbosity

I wrote a lengthy reply to Michael explaining the risks to his blog. I’d like to share some of that with you. In fact, I want to share this with as many people as I can.

If you know of ANYONE that is still running an older version of WordPress, please refer them to this post They need to update their blog. If they haven’t upgraded yet, they simply don’t understand the risks involved. This post give them the risks – short and sweet – and also gives some specific details about one way your site could be attacked.

I’m going to be very frank in the rest of this post. I really hope this doesn’t bother too many people. I know it will bother some even though I’m not going to provide the exact implementation details of any attack. Some people will argue that just telling people it can be done is the same as providing source code, but I would remind those people of the release dates for the versions I’m talking about:
Version 1.2 May 22, 2004
Version 1.5 Feb 14, 2005
Version 2.0 December 26, 2005

It has been over a year since 2.0 was released. There has been sufficient time for people to update since then. Version 2.0.6 is a due out this month with 2.1 chasing at its heals. There is simply no excuse, but ignorance of the danger, not to have updated their site by now. And pleading ignorance isn’t gonna get your posts back.

Where WordPress Stands

I don’t know of any search that will tell me EXACTLY how many people are still running each version, but I’ve tried to come up with some estimates: (This section was rewritten in October and this post has been sitting in the draft folder for a while since then. If follow these links, you will have differring results.)
Version 1.274,600 Sites (down from 127,000 sites 3 month ago)
Version 1.5679,000 Sites ( down from 1.1 million)
Version 2.0-2.0.224.5 million sites (up from 3.9 million)
This far out strips the “safer” versions: (Those after NONCEs were introduced.)
Version 2.0.30.744 million sites (up from 0.5 million)
Version 2.0.42.3 million sites (up from 0.5 million)
Version 2.0.50.877 million sites

The scary thing is how much the older releases have grown since I started tracking these numbers back at the end of July. There are 6 times the number of vulnerable sites now as there were in July. That’s the change in just over 3 months. (It is now December and I’ve not re-run the queries. I wonder if this trend continued…)

UPDATE:


Here are the numbers as of Dec. 12 2006
Version 1.2 – 52,500 down form 74,600 in two months
Version 1.5 – 515,000 down form 679,000 in two months
Version Version 2.0-2.0.2 – 1,160,000 down form 24.5 million sites – 1.16 million is still a lot, but this world is a LOT better…than Google painted it in October. Given the progression, perhaps they had an order of magnitude issue???

NOTE: These numbers might be high because of old and duplicate finds or they may just as easily be low because themes often remove the text I am looking for. We do know that as of the 2.0.5 release there were 1.2 million downloads from the main site. Many admins run dozens or hundreds of WordPress sites and there are other places to download the software. So, these figures might just be accurate.

5 Comments

Add a Comment

Your email address will not be published. Required fields are marked *