Vulnerability in WordPress 4.7.0 and 4.7.1

A serious vulnerability has been reported in recent versions of the WordPress core files which can overwrite your posts or pages with undesirable text. This is called content injection, and if you’d like to read the technical details of how this works Click Here.

As a courtesy to all our customers who are using versions 4.7.0 and 4.7.1, we have updated your sites free of charge to WordPress 4.7.2. This version of WordPress has had this problem fixed.

Basically, in layman’s terms, a hacker can use a hidden part of WordPress to send information directly to the content management system (even though they are not logged in), and overwrite posts and pages with whatever they like.

Using this exploit, there is a way for a hacker to run malicious code on your website by using special plugins that you may have already installed. Insert PHP and Exec-PHP are two of the most popular plugins that can be freely downloaded from the WordPress Plugin Repository and allow code execution. These plugins allow PHP code to be executed on your site directly within a page. PHP is the programming language that WordPress is written in, and a hacker can use it to change most aspects of your website.

N.B. We believe that PHP should never be run directly with a post or a page, and we never use these plugins within the sites that we create. However, if you have installed them yourself, we feel that you should remove them and talk to us if you require custom programming work adding into your system.

We do have services to keep your site and its plugins updated on a monthly basis at very reasonable price. We make all changes to a test site where every thing is checked before we apply changes to your live site. Please take a look at our maintenance page and contact us for more information.