Stats Plugin Vulnerability

Anyone hosting their own blog and running the WordPress.com Stats plugin should update the plugin to version 1.1.1 immediately or apply the patch below. A critical SQL injection vulnerability was found and fixed. The bug could allow an attacker to steal administrative credentials. (WordPress.com bloggers are not affected.)

Most users will want to download the latest version and simply copy the new files directly over the old ones. Subversion users may do `svn up`. Advanced users may apply the patch manually.

Thanks to Alex Concha who found and reported the bug to me. He also provided the fix.

18 Comments

Filed under Plugin, Security, Stats, WordPress

18 Responses to Stats Plugin Vulnerability

  1. Pingback: WordPress.com Stats Vulnerability | Joseph Scott's Blog

  2. Pingback: www dot james mckay dot net » I could have told you this would happen...

  3. Pingback: Stats Plugin Vulnerability | Crucial Thought

  4. Question: what if we didn’t upgrade to 1.1? Are we at risk?

  5. Pingback: Top Posts « WordPress.com

  6. Pingback: » Wp-Plugin WordPress.com Stats » WordPress Italy

  7. machmoth

    Is it just me, or is there a tiny smile watching over me on the side of the new iframe? I see you smiley!

  8. Pingback: Worpress.com Stats Plugin Vulnerability : JaypeeOnline | Blogging News & Reviews

  9. Pingback: WordPress.com Stats Plugin 1.1 - pestaola.gr

  10. Pingback: WordPress.com 統計外掛 1.1.1 版 « Kirin Lin

  11. Pingback: Wordpress.com Stats Plugin: Upgrade to version 1.1.1 | InvestorBlogger

  12. @Jonathan: yes, unless you manually fix the problem.

  13. Pingback: PandaCube - A Digital Notebook » Blog Archive » Critical Update on WordPress.com Stats Plugin

  14. alder

    is it intended that i dont see the ‘Blog Stats’ link in my dashboard when i’m not logged in as administrator? as normal user (even editor) i still just have the ‘Visit your Global Dashboard to see your blog stats.’-link there.
    actually i dont want to be logged in as admin all the time :/

  15. Pingback: Critical Update for WordPress Self Hosted Blog Stats « A Guilty Pleasure

  16. Pingback: Wordpress Plugin: Wordpress Stats Update to v1.1.1 at The OS Quest

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s