WordPress 1.5.1.3 now available.

Just 3 hours ago, WordPress released the latest security upgrade for StrayHorn v1.5.1.3 . Go ahead an upgrade your blogs.

After the recent security breach of PCIJ’s blog, I believe that bloggers will be more aware of the importance of regularly updating their web softwares. Along with WP, PHPNuke and PhpBB are two of the most widely exploited web apps. WP is quick in releasing patches and updates, while phpBB (now v2.0.16) regularly releases new updates as well.

Anyone who knows about the vulnerability can easily exploit them and your site might just be the unlucky target. PCIJ is still lucky the script-kiddie (not a hacker as popularly dubbed) only had limited access to their hosting account and logged in thru a WP hole, otherwise he/she could have wiped out all the files.

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 998 other subscribers
Avatar for Abe Olandres

Abe is the founder and Editor-in-Chief of YugaTech with over 20 years of experience in the technology industry. He is one of the pioneers of blogging in the country and considered by many as the Father of Tech Blogging in the Philippines. He is also a technology consultant, a tech columnist with several national publications, resource speaker and mentor/advisor to several start-up companies.

12 Responses

  1. Avatar for Porn Search Engine Porn Search Engine says:

    Please visit this Porn Search Engine to search for movies and pictures.

  2. Avatar for Abe Olandres Abe Olandres says:

    Here’s an in-depth dissection of the changes in WP 1.5.1.3: http://elliottback.com/wp/archives/2005/06/29/wordpress-153-security-fixes/

  3. Avatar for markku markku says:

    Only 4 core files were changed:

    xmlrpc.php
    wp-admin/post.php
    wp-includes/functions-post.php
    wp-includes/version.php

  4. Avatar for Fleeb Fleeb says:

    How about asking the WP guys to allow placing of their WP includes outside of public_html? Hmm…

  5. Avatar for Migs Migs says:

    install Apache mod_security if you can.

  6. Avatar for AnP AnP says:

    i upgraded pero I can’t see the diff.

  7. Avatar for Abe Olandres Abe Olandres says:

    @ hoop

    Now that you mentioned it… ;) :D

  8. Avatar for mr nice ash mr nice ash says:

    probably. but it can be helped always.

  9. Avatar for hoop hoop says:

    I think it would be best practice to add a web directory password for the wp-admin folder. Would in effect add another security layer to the site.

  10. Avatar for Abe Olandres Abe Olandres says:

    Just upgraded myself… :D

    @Jaypee, someone got a user level to enable them to post an entry. That’s all that was done actually.

  11. Avatar for Jaypee Jaypee says:

    Salamat sa update. Ano nangyari sa blog ng PCIJ? nadelete ang ibang files? na vandalize ba? :D

Leave a Reply
JOIN OUR TELEGRAM DISCUSSION

Your email address will not be published. Required fields are marked *