{"id":952,"date":"2007-03-05T22:54:08","date_gmt":"2007-03-06T03:54:08","guid":{"rendered":"http:\/\/studytools.psych.und.nodak.edu\/wordpress\/?p=952"},"modified":"2007-03-06T10:49:55","modified_gmt":"2007-03-06T15:49:55","slug":"wordpress-dangerous-upgrade","status":"publish","type":"post","link":"https:\/\/learningaloud.com\/blog\/2007\/03\/05\/wordpress-dangerous-upgrade\/","title":{"rendered":"WordPress Dangerous &#8211; Upgrade"},"content":{"rendered":"<p>WordPress dangerous &#8211; upgrade immediately!!<\/p>\n<p>I hate running into messages like this after I am home and settled down for an hour of relaxing reading before heading off to bed. By chance, I was scanning the <a href=\"http:\/\/web2.commongate.com\/post\/WordPress_2_1_1_dangerous_Upgrade_to_2_1_2\">web2.ohh<\/a> blog and encountered an urgent message to WordPress users.  Supposedly, a cracker gained access to the WordPress servers and inserted malicious code in the upgrade available for download. I think I upgraded before the date this exploit supposedly was added, but it was not worth taking the risk. So, it was back to the office to install the upgrade. I must stay on the good side of the security people.<\/p>\n<p>I must admit I have wondered about this before. Wouldn&#8217;t joining an open source project and inserting malicious code in a component offer a relatively easy way to insert access opportunities in many servers? I suppose the open source community examines contributions carefully. This was not the reported cause of the WordPress problem because scripts in a couple of WordPress modules were modified after being approved for distribution. As I understand the danger, the modules would allow PHP code to be submitted remotely in a form that would be run by the server. In contrast, if I would enter PHP commands as I enter the text for this blog, the PHP commands should not be interpeted.<\/p>\n<p>echo &#8220;hi&#8221;;<\/p>\n<p>The night watchman always says the same thing &#8211; &#8220;Working late Dr. Grabe?&#8221;<\/p>\n<div class=\"pvc_clear\"><\/div>\n<p id=\"pvc_stats_952\" class=\"pvc_stats all  \" data-element-id=\"952\" style=\"\"><i class=\"pvc-stats-icon medium\" aria-hidden=\"true\"><svg aria-hidden=\"true\" focusable=\"false\" data-prefix=\"far\" data-icon=\"chart-bar\" role=\"img\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewBox=\"0 0 512 512\" class=\"svg-inline--fa fa-chart-bar fa-w-16 fa-2x\"><path fill=\"currentColor\" d=\"M396.8 352h22.4c6.4 0 12.8-6.4 12.8-12.8V108.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v230.4c0 6.4 6.4 12.8 12.8 12.8zm-192 0h22.4c6.4 0 12.8-6.4 12.8-12.8V140.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v198.4c0 6.4 6.4 12.8 12.8 12.8zm96 0h22.4c6.4 0 12.8-6.4 12.8-12.8V204.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v134.4c0 6.4 6.4 12.8 12.8 12.8zM496 400H48V80c0-8.84-7.16-16-16-16H16C7.16 64 0 71.16 0 80v336c0 17.67 14.33 32 32 32h464c8.84 0 16-7.16 16-16v-16c0-8.84-7.16-16-16-16zm-387.2-48h22.4c6.4 0 12.8-6.4 12.8-12.8v-70.4c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v70.4c0 6.4 6.4 12.8 12.8 12.8z\" class=\"\"><\/path><\/svg><\/i> <img loading=\"lazy\" decoding=\"async\" width=\"16\" height=\"16\" alt=\"Loading\" src=\"https:\/\/learningaloud.com\/blog\/wp-content\/plugins\/page-views-count\/ajax-loader-2x.gif\" border=0 \/><\/p>\n<div class=\"pvc_clear\"><\/div>\n","protected":false},"excerpt":{"rendered":"<p>WordPress dangerous &#8211; upgrade immediately!! I hate running into messages like this after I am home and settled down for an hour of relaxing reading before heading off to bed. By chance, I was scanning the web2.ohh blog and encountered an urgent message to WordPress users. Supposedly, a cracker gained access to the WordPress servers &hellip; <a href=\"https:\/\/learningaloud.com\/blog\/2007\/03\/05\/wordpress-dangerous-upgrade\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">WordPress Dangerous &#8211; Upgrade<\/span><\/a><\/p>\n<div class=\"pvc_clear\"><\/div>\n<p id=\"pvc_stats_952\" class=\"pvc_stats all  \" data-element-id=\"952\" style=\"\"><i class=\"pvc-stats-icon medium\" aria-hidden=\"true\"><svg aria-hidden=\"true\" focusable=\"false\" data-prefix=\"far\" data-icon=\"chart-bar\" role=\"img\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewBox=\"0 0 512 512\" class=\"svg-inline--fa fa-chart-bar fa-w-16 fa-2x\"><path fill=\"currentColor\" d=\"M396.8 352h22.4c6.4 0 12.8-6.4 12.8-12.8V108.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v230.4c0 6.4 6.4 12.8 12.8 12.8zm-192 0h22.4c6.4 0 12.8-6.4 12.8-12.8V140.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v198.4c0 6.4 6.4 12.8 12.8 12.8zm96 0h22.4c6.4 0 12.8-6.4 12.8-12.8V204.8c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v134.4c0 6.4 6.4 12.8 12.8 12.8zM496 400H48V80c0-8.84-7.16-16-16-16H16C7.16 64 0 71.16 0 80v336c0 17.67 14.33 32 32 32h464c8.84 0 16-7.16 16-16v-16c0-8.84-7.16-16-16-16zm-387.2-48h22.4c6.4 0 12.8-6.4 12.8-12.8v-70.4c0-6.4-6.4-12.8-12.8-12.8h-22.4c-6.4 0-12.8 6.4-12.8 12.8v70.4c0 6.4 6.4 12.8 12.8 12.8z\" class=\"\"><\/path><\/svg><\/i> <img loading=\"lazy\" decoding=\"async\" width=\"16\" height=\"16\" alt=\"Loading\" src=\"https:\/\/learningaloud.com\/blog\/wp-content\/plugins\/page-views-count\/ajax-loader-2x.gif\" border=0 \/><\/p>\n<div class=\"pvc_clear\"><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[1],"tags":[],"class_list":["post-952","post","type-post","status-publish","format-standard","hentry","category-general"],"a3_pvc":{"activated":true,"total_views":12,"today_views":0},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p1zo8Q-fm","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/posts\/952","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/comments?post=952"}],"version-history":[{"count":0,"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/posts\/952\/revisions"}],"wp:attachment":[{"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/media?parent=952"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/categories?post=952"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/learningaloud.com\/blog\/wp-json\/wp\/v2\/tags?post=952"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}