WordPress 2.5 Vulnerability Requires WordPress 2.5.1 Upgrade
Posted by Snap! on April 27th, 2008
As you may have noticed, we are missing a few blog posts (nothing significant) and some comments as a result of a recent database issue which is being investigated. Just so you are warned, multi-author WordPress install such as our own site should not be running version 2.5 for the reason we all have come to know as CVE 2008 1930. Upgrading to version 2.5.1 now will save you a lot of hassle, trust me us this.
We believe a recent attack on our site due to that WordPress vulnerability was responsible for the issues we encountered lately. We assure you that we have taken all the steps necessary to rectify it. Although the BBPress powered WP News Forum was linked, we were able to restore all the fields and posts without any loss of data.
Here are some symptoms and diagnosis for the issue:
http://wordpress.org/support/topic/172004
http://wordpress.org/support/topic/168964
We will post a detailed step by step correction process once we confirm the issue was indeed related. Although having a backup of your database from pre-2.5 might help, we feel it can be accomplished without any backup.
Sunny has a post detailing some WordPress 2.5 troubleshooting tips!




April 28th, 2008 at 8:40 am
Hope it helps! I am not too thrilled with version 2.5 especially on security. It looks fabulous though!
May 10th, 2008 at 7:03 am
Does this also applicable to blogs hosted on wordpress.com