Old WordPress Versions Under Attack
Otto42 of OttoDestruct, a key WordPress developer and supporter, reports that there is an “attack” on older versions of WordPress right now. The number of sites hit by this is growing every hour. Protect your WordPress blog now: UPDATE NOW!!!
Context & Ripple Effects
OttoDestruct's Otto42, a core WordPress developer and supporter, reports an active attack sweeping older WordPress installs, with affected-site counts rising by the hour and an immediate-upgrade plea going out on September 4, 2009. This is not the platform's first emergency: in March 2007 the project was forced to push everyone off a compromised 2.1.1 release, and in December 2007 it shipped an urgent 2.3.2 fix for a bug exposing draft posts.
First-order effects
- Bloggers still running pre-2.8 builds — the 'Baker' release shipped in June 2009 but adoption among self-hosters is uneven — are the direct targets, and every hour of delay adds compromised sites to the tally Otto42 says is growing continuously.
- The WordPress team shifts into emergency-response mode: getting the upgrade notice in front of millions of independently administered blogs becomes the defense, since there is no central operator to patch for them.
Second-order effects
- Rivals get ammunition: Six Apart already ran a campaign targeting WordPress users in 2008, and a visible wave of hacked blogs gives hosted competitors a trust argument against self-hosting.
- Hosts and the plugin ecosystem absorb the cleanup burden — broken, spam-injected installs drive support load and renew the case for easier in-dashboard updating, a path WordPress began building with 2.5's one-click upgrades.
Third-order effects
- If the pattern holds, the structural weakness is version fragmentation itself: a platform whose install base spans many old releases can only be as secure as its least-updated user, pushing WordPress toward making security upgrades automatic rather than optional.
- Recurring emergency-update cycles also harden the split in the blogging market between managed services that patch centrally and self-hosted software where every admin is their own security team.
The trend: Self-hosted publishing platforms face a recurring cycle in which attackers exploit the long tail of unpatched installs, forcing vendors to trade admin control for automatic security updates.