WordPress 3.zero.2 Is Out – Now Can Be A Great Time To Update
WordPress has released a mandatory update for all previous versions of the blogging platform. The update, which is a maintenance release, addresses several security issues, including one that will allow a malicious author additional access to the site.
WordPress 3.0.2 is out – now would be a good time to update
In a breakdown of the fixes, WordPress said the moderate security issue that allows a malicious author the ability to gain additional access is the most important fix in the update. Even if you have no other authors, or trust the authors on your site, they still ask that everyone update their installations. Additional fixes include XSS (Cross-Site-Scripting) fixes, as well as other hardening measures.
The additional hardening, as well as the fact that the author issue affects all known versions of WordPress prior to 3.0.2, is the best reason to upgrade. However, the fact that WordPress is an ever-increasing attack vector should also be a consideration. Moreover, by keeping your WordPress installations current, you are doing a service to everyone online.
Criminals target outdated installations, as well as abandoned installations of WordPress, to push Malware, propagate scams, or leverage the site in BlackHat SEO attacks. Keeping your site updated, or removing WordPress if you are not using it, severely limits the criminals access to source materials for their crimes.
Recently, more than 600 WordPress installations were attacked and used to deliver malicious JavaScript files that push Malware from a remote location. Each site used a different WordPress version, and they were hosted by the same company. Sophos has more details here.
While it isnt a silver bullet method of website security, updating the software is a solid step, and youll protect others by removing your site from the list of potential attack points.
In addition to the core software, care should be taken to update WordPress plugins as well. A quick search shows plenty of vulnerabilities that can be exploited by a criminal to attack your site. When you have a chance to update something, it is often better to do it sooner rather than later.
WordPress offers additional guidance for hardening installations against attacks. Webmasters who rely on WordPress to publish content should take a moment and read up on these tips. Should you find that your site has been compromised, there are some additional steps to take. WordPress has offered advice for this too.
Updating your WordPress installation is as simple as downloading the newest version, or clicking the update button on your administration dashboard. See the updates menu to do so.
As stated in the WordPress blog, this Haiku sums things up nicely:
Fixed on day zero
One-click update makes you safe
This used to be hard