Hey! It's Joelle!

WassupPluginforWordpressSecurityVulnerability

Friday,May15,2009 How-To PleaseStandBy

Due to a security vulnerability in a 3rd-party Wordpress plugin called Wassup, one of our clients had their site hacked and their RSS feeds inserted with warez links and spam-like info.  We recommend that if you are running the Wassup plugin, you deactivate in the plugin in the Wordpress control panel and find an alternate source of stats tracking.  We like Mint!

How to deactivate & remove your Wassup plugin:

  1. Go to your Wordpress Dashboard.
  2. Find “Plugins” on the left sidebar and drop the menu open by clicking the arrow on the right that will appear when you hover over it. (It menu may already be visible.)
  3. Choose “Installed Plugins”.
  4. From the list that loads on the right, find the Wassup plugin and click the “Deactivate” link on the right.
  5. If you also have VSTATS plugin installed,we recommend deactivating that as well.
  6. Once that’s done, log into your server using FTP (or if you manage your files via server control panel interface, that’s fine, too) and go to /public_html/wp-content/plugins/ and remove the entire /wassup folder, as well as the vstats.php file.

Now, just because you have this plugin, doesn’t mean your computer has been hacked, it just means it’s vulnerable to it.  So deactivating and removing the plugin should resolve the issue.  If you are one of our clients for whom we installed this plugin and for some reason, you feel your site has been hacked or otherwise compromised by Wassup (bear in mind we’ve only received one report), please contact us and we will do our best to assist*.  (More information)

Thank you!

 

* Please note that Moxie Design Studios™, it’s designers and/or contracted developers are not liable for damages caused by a third party plugin security vulnerability, nor the existence of the vulnerability itself. Plugins and software related to Wordpress are open source, as well as free, and there is an element of risk to any Internet-related endeavor.

add to sk*rt Bookmark to del.icio.us Add to Technorati favorites Digg this post on digg.com
Sorry, folks. Comments are closed for this entry.
United States
Picture of Jason Deans Jason Deans on May 23, 2009 at 6:24am

I stumbled across your blog (love it btw) and noticed your post on Wassup.  Thanks for the heads up on this vulnerability. 

Raleigh Interior Design

India
Picture of seo services seo services on May 23, 2009 at 1:08pm

THANKS FOR THIS POST ,GO AHEAD..

Malaysia
Picture of Web Design Company Web Design Company on May 31, 2009 at 11:25pm

Thanks for the warning and solution to this security vulnerability. Highly appreciated. Keep posting.

Australia
Picture of web design web design on June 9, 2009 at 10:46pm

I need to implement + key for inserting a line in the textbox and key for submitting the form…if any one could help me

http://www.inowweb.com

Germany
Picture of fashion and vintage fashion and vintage on June 10, 2009 at 4:02am

I LOVE your site!! Thanks for the good information! I stumbled fashion and vintage across your blog (love it btw) and noticed your post on Wassup.  Thanks for the heads up on this vulnerability. Thank you for sharing! Have a great day.

Commenting is not available in this weblog entry.