Worpress.com Stats Plugin Vulnerability

28. Jul 2007 · 1498 Views ·

Blog



This is an update to my recent post Wordpress.com Stats Plugin Upgrade.

Andy Skelton, one of the plugin developer’s talks about it in his blog:

Anyone hosting their own blog and running the WordPress.com Stats plugin should update the plugin to version 1.1.1 immediately or apply the patch below. A critical SQL injection vulnerability was found and fixed. The bug could allow an attacker to steal administrative credentials. (WordPress.com bloggers are not affected.)

Most users will want to download the latest version and simply copy the new files directly over the old ones. Subversion users may do `svn up`. Advanced users may apply the patch manually.

Download the latest version of Wordpress.com Stats plugin.

, , , ,




Related Ads

Related Posts




















2 Responses to “Worpress.com Stats Plugin Vulnerability”

  1. Jaypee Firefox 2.0.0.5 Windows XP Says:

    @trench - Those that are at risk are the ones using the Wordpress.com Stats plugin. You’re okay. ;)

  2. trench Firefox 2.0.0.5 Windows XP Says:

    so does this include me? Is this stats plugin come standard or only if we use it? Im using firestats…

GoDaddy.com SmartSpace

Leave a Reply


Live Comment Preview