I don't feel safe with Wordpress, hackers broke in and took things
A few weeks ago some hackers broke into my blog here (this was before 2.8.4 was released). At first I thought they just left some porn sites in a couple of blog entries. So we upgraded Wordpress (I was on 2.7x back then).
Context & Ripple Effects
This is the second time in roughly two years that WordPress has had to tell its user base to upgrade or get burned: back in March 2007 a compromised 2.1.1 download forced an emergency move to 2.1.2, and the day before Scoble's post, Lorelle documented that old WordPress versions were under active attack. What changed here is that the victim is one of the platform's most-watched voices — Robert Scoble — writing that he 'doesn't feel safe' after hackers inserted porn links into his 2.7x blog.
The story traveled far enough that WordPress itself published 'How to Keep WordPress Secure' around the same date, effectively conceding that running an unpatched self-hosted install had become a real liability rather than a theoretical one.
First-order effects
- Self-hosted bloggers still running pre-2.8.4 installs are directly exposed to the same injection attack Scoble described, and his post turns upgrading from routine maintenance into an urgent fix.
- WordPress takes a trust hit at exactly the moment its adoption is widening — a high-profile blogger publicly saying he no longer feels safe on the platform.
Second-order effects
- Hosting providers and theme/plugin sellers face support load from a wave of manual upgrades, since every out-of-date install is now a visible compromise vector.
- Rival hosted publishing services gain a sales argument against self-hosted WordPress: someone else patches the core for you.
Third-order effects
- If old-version attacks keep recurring, the structural answer is automatic security updates as a default in web publishing software — ending the era where keeping a blog safe depended on each owner manually applying patches.
The trend: Active exploitation of stale self-hosted installs is pushing blogging platforms toward vendor-managed, automatic patching as the baseline security model.