I've just found a hacked wordpress site
checked the meta generator was wordpress 3.2.1
googled it and found this --> [link removed]
an XSS attack, is this true?
the hacked site --> http://sexygirltoday.com/
I've just found a hacked wordpress site
checked the meta generator was wordpress 3.2.1
googled it and found this --> [link removed]
an XSS attack, is this true?
the hacked site --> http://sexygirltoday.com/
Sites get hacked via other points of entry on their servers all of the time. There are no known security issues in WordPress 3.2.1
And don't post links to hack codes, fer pete's sake! If you think you have uncovered a genuine security issue, please email security@wordpress.org
sorry, just curious
I'll strip the link
then mark this closed
sorry
edit:
okay, I'll send to that email
because I have 3 running site with wordpress
and this makes me worry
I asked one of the core devs to have a look at the script - just in case - and it seems to have been a false alarm. :-)
You must log in to post.