
More than 1,000 WordPress blogs have been modified to redirect visitors to sites serving malware, affiliate and pay-per-click redirectors, and low quality PPC search result aggregators, through the WordPress' automatic update feature.Commentary:
The individuals behind the attack have discovered how to add the malicious code to the update.php file, which prompts WordPress to update. This code then injects other code in the wp-settings.PHP file, and effects the redirects.
The update.php file contains the "wp_update_core" function, which is used by the WordPress Automatic Update feature, says Sinegubko.
For years web developers and WordPress developers will told the world and their clients if you want to keep your site secure, you need to keep it updated. The best (easiest) way to do that is simply to run auto updates (within reason) when they come available.
The most common WordPress updates, WordPress theme updates and WordPress plugin updates are security updates. Someone finds a weakness,...






Recent Comments