Sorry this site requires JavaScript to be enabled in your browser. See the following guide on How to enable JavaScript in Internet Explorer, Netscape, Firefox and Safari. Alternatively you may be blocking JavaScript with an advert-related or developer plugin. Please check your browser plugins.

IMO the only way to be secure for right now is to run the last build before 2.5 & update it with all security patches - then if you are worried about sites not accepting your blog because its under 2.5 - simply go into your header.php in your template directory and change the meta tag from ...

meta name="generator" content="WordPress
Comments8 Comments  

Comments

Avatar
from streko 1504 Days ago #
Votes: 0

Change meta tag from...meta name="generator" content="WordPress bloginfo(’version’) "(there is standard php stuff in there but old sphinn won’t let me have them in the post.)tometa name="generator" content="WordPress 2.5"

Avatar
from tnash 1504 Days ago #
Votes: 2

Interesting I suspect this might make http://sphinn.com/story/40009 a bit more relevant though it should be pointed out this could potentially effect other versions as well.

Avatar Moderator
from nowsourcing 1504 Days ago #
Votes: 1

I sphunn as the securityfocus site is relavent, however all previous versions of WordPress are at risk.Yeah, what Tim said.

Avatar
from mvandemar 1504 Days ago #
Votes: 0

Damn it.Ok, so... 2.3.3 is not listed, but we never heard from WP on this one:New Wordpress 2.3.3 Exploit/Vulnerability - Adds Spam Directory /wp-content/1/So, not sure what the best approach would be.

Avatar
from streko 1504 Days ago #
Votes: 0

customize your code so much that it becomes your own version.with WP being open source im kinda surprised no group has taken the code and just made it crazy secure and then redistributed it so it would still run plugins and templates like normal.

Avatar
from Jeeb90 1504 Days ago #
Votes: -1

I would like to see someone take it and make a secure closed-source version.  Then have them be responsible for making sure it still works with future plugins etc and everytime a new version is released. I’d be willing to pay for that.  I wonder if there’s a programmer willing to do that.  And a person willing to be in charge of such a project.There could be very good money in that if it’s the real deal.  Charge people yearly.

Avatar
from markymark 1502 Days ago #
Votes: 1

Well, there’s a surprise. I’m with Jeeb90 - a paid, closed source version is the way to go. I’d pay just to avoid the tediousness of updating my WordPress blogs every 27 minutes or so.

Avatar
from SpostareDuro 1501 Days ago #
Votes: 0

do we really wait 27 minutes? i thought it more frequently than that..hmm

Upcoming Conferences

Search Marketing ExpoSearch Engine Land produces SMX, the Search Marketing Expo conference series. SMX events deliver the most comprehensive educational and networking experiences - whether you're just starting in search marketing or you're a seasoned expert.



Join us at an upcoming SMX event:

Upcoming Webcasts

Search Marketing Now Learn more about search marketing with our free online webcasts and webinars from our sister site, Search Marketing Now. Upcoming online events include: