Home » WordPress News

Wither Art Thou, WordPress 2.6.4?

With this week’s release of WP 2.6.5, you might be wondering where 2.6.4 went.

It didn’t – in fact, there will NEVER be a WordPress 2.6.4 – because there already was one!

Confusing I know, but the catch is that another site tried to release a WP 2.6.4 with some malware in it – and the result was that the official WP release number was bumped up to avoid any confusion.

The fake 2.6.4 included some nasty code in the /wp-includes/pluggable.php file which tried to send cookie data to another site (which tried hard to look like wordpress.org, even naming itself wordpresZ.org).

With these cookies, it may have been possible to hack into others’ blogs – and have complete control of the site.

So if you see WP 2.6.4, avoid it like any other malware out there.

Digg this! Add to del.icio.us! Stumble this! Add to Techorati! Share on Facebook! Seed Newsvine! Reddit! Add to Yahoo!

Leave your response!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.