WordPress hacked – it was OptimizePress 1.43

Hi,

one of my smaller blogs got hacked on friday the 25th.

2 files got infected, I cant say if the database is infected (just restored a 1 week old backup to be save).

I found 2 files infected (so far.. )

config.inc.php
version.php

I did some research and found out: it was OptimizePress!

It was OptimizePress that allowed my wordpress blog to be hacked!

They offer a german (old) 1.43 version, that hat the faulty timthumb exploit. I used it on my german squeeze page and got hacked…

A few days ago, they released 1.45 in german..

I checked other languages, like french an spanish, the offer the insecure 1.43 in those languages.

THATS BAD!

This exploit is 4 months old, and they do nothing to secure their customers!

And the secure 1.45 was released just a few days ago.. Thats about 4 months of unsecure wordpress template!

French, russian, spanish? DONT USE IT!

So? How can this be?

This entry was posted in Wichtige WordPress Plugins. Bookmark the permalink.

Comments are closed.