A few words about the RISKS of WordPress 1.2, 1.5, 2.0 or anything less than 2.0.4

How can you make a difference?

1. Upgrade your blog and explain why you did it.
This is the best way to protect WordPress from getting a bad name it doesn’t deserve. The WordPress developers have taken steps to make it a safe system, but only you can upgrade your site.

2. Write an article on your blog.
I’ve made this post as long as it is so that people can have enough material to write their own posts quickly and easily. URGE YOUR READERS TO UPDATE THEIR OWN BLOGS.

3. Use Google to find blogs that haven’t updated and ask them to upgrade to a safe version.
Here are the searches for the most vulnerable sites:
Version 1.2
Version 1.5
Version 2.0-2.0.2

Make a comment or send the admin an email telling them to upgrade. Link to your article or mine, I don’t care. Here’s some sample text, you can replace the link to this article with a link to your own:

Hi! I see you are running an older version of WordPress. Did you know that just about anyone can get into your site and delete your posts? PLEASE update to a version of WordPress that was written in the last year. We don’t want WordPress to get a bad name in the security world just because a few people don’t update. Here’s an article explaining the risks:
<a href=”http://www.thecodecave.com/article249″ title=”You really should upgrade”>A few words about the RISKS of WordPress 1.2, 1.5, 2.0 or anything less than 2.0.4</a>. If I can find your site and tell you to update, so can the hackers who will want destroy your site.

Those are three easy tasks. You have a choice. Do you help your fellow blogger by saving them the heartache of a lost site, or do you ignore the issue? I couldn’t ignore the issue. I hope you can’t either.

Post script

This post was started a long time ago and has gone through many revisions and I debated where I fell on the Obscure/Announce debate. I’d originally planned to briefly explain how to do each of the first six attacks I mentioned. However, I’ve backed off on that. I think I’ve given sufficient detail, that actual code would help make things clearer. This post is long enough as it is and it is important enough that I don’t want to delay any longer. Giving more detail will only cause fewer people to reach the end of the article. If you can think of other ways to improve the impact of this article, please let me know. I’m sure there will be spelling mistakes, grammar mistakes and more. Just leave a comment on the page with the problem, and I’ll clean it up. Thanks!- B

5 Comments

Add a Comment

Your email address will not be published. Required fields are marked *