WordPress 3.7 now contains an auto-updater

The machines we love to hate

Moderator: Wiz Feinberg

User avatar
Wiz Feinberg
Posts: 6113
Joined: 8 Jan 1999 1:01 am
Location: Mid-Michigan, USA

WordPress 3.7 now contains an auto-updater

Post by Wiz Feinberg »

I have waited a long time to read the news that one of the Web's more popular and exploited blog frameworks has been updated to a new version that will henceforth update itself!

WordPress.org has just released WordPress 3.7; a.k.a: "Basie," in honor of Count Basie. If you operate a website and have installed any previous version of WordPress, whether through a one-click or manual installation, update it now. Then verify in the preferences that automatic updating is enabled.

WordPress, along with Joomla are the two most targeted web programs being probed at this point in time. An outdated version of the program, or one of its plug-ins, can allow a complete takeover. Takeovers are used to inject malicious iframes into the blog pages, attacking your readers' browsers when they visit your blog or website.

Also, review any and all plug-ins you have installed into either WordPress or Joomla. Some are no longer supported at all and are easy targets for such attackers as "Bot for JCE."

As always, protect your admin login with a very strong password. Using the default password leaves the door wide open to any script kiddie. The new version will even offer to create one for you.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
User avatar
Cal Sharp
Posts: 2874
Joined: 4 Aug 1998 11:00 pm
Location: the farm in Kornfield Kounty, TN

Post by Cal Sharp »

Auto update sounds good, thanks for the heads up, Wiz. I updated one of my WP sites just now and it went smoothly. Now I gotta do the same for my clients' sites. But I guess it'll be the last time I'll have to do it myself.

I might mention that some WP sites were hacked recently that had admin as the user name, so it's a good idea not to use that.
C#
Me: Steel Guitar Madness
Latest ebook: Steel Guitar Insanity
Custom Made Covers for Steel Guitars & Amps at Sharp Covers Nashville