Bruce Boardmeister

Joined: 06 Jun 2005 Posts: 7977 Location: Portland, OR
|
Posted: Fri Jul 25, 2014 9:26 am Post subject: Trouble for Word-Press based sites |
|
|
I got this message from my ISP. If you designed your site using WordPress this may (or may not) be a concern for you:
This alert applies to WordPress websites using the popular MailPoet plugin. Immediate action is required for users of this plugin.
A major vulnerability in the popular WordPress plugin MailPoet is currently being widely exploited.
This vulnerability is allowing attackers to inject malware and other malicious code onto sites using outdated versions of the plugin. In fact, this vulnerability is so significant, attackers may be able to inject absolutely anything they want onto your site, leaving you and/or your business open to a number of dangers beyond a simple site hack.
It is important for us to stress that the ongoing, aggressive exploitation of this vulnerability is very large in scale, and the assumption should be that your WordPress site - if you’re using the plugin - will be targeted and exploited, if it has not already happened.
For more details and reportage on this vulnerability, please click http://blog.sucuri.net/2014/07/mailpoet-vulnerability-exploited-in-the-wild-breaking-thousands-of-wordpress-sites.html and http://seclists.org/oss-sec/2014/q3/239
Please Take Action Now
If you are currently using MailPoet (or think you may be using it), please take immediate action to secure your website. Specifically, update the plugin if you haven’t done so already.
If you’re not sure if you use this plugin, we highly advise that you find out right away.
You can check and update your plugins through your WordPress dashboard. You can also visit the MailPoet plugin page https://wordpress.org/plugins/wysija-newsletters/ _________________ VO-BB Member #31 Enlisted June, 2005
I'm not a Zoo, but over the years I've played one on radio/TV. . |
|