This vulnerability allows remote attackers to access the servers of all sites using early versions of these plugins. We expect numerous websites to potentially be at risk and are moving to help buyers secure their sites immediately.
more: http://themeforest.net/forums/thread/important-serious-vulnerability-in-revolution-slider-showbiz-pro-wordpress-plugins/141396?page=1&_ga=1.170983012.515219436.1410563085
tagDiv?
That post is 8 days ago. Since then the issue has been brought to tagDiv’s attention and the plugin is the updated, secure version in the latest theme update.
This was covered here on the forum recently. I actually spoke to the folks who make Revolution Slider, and the product was patched 29 versions ago. Meaning, RS 4.12 technically. All versions after that were patched.
So, if you have the current theme update 4.2 or later which includes RS Version 4.3.8 SkyWood (27th April 2014), you don’t need to worry about it. Good reason to keep your theme updated, or download the latest plugins which are bundled with each theme update.
SEE:
https://forum.tagdiv.com/topic/hacking-issues-with-rev-slider/
And it’s good they are warning people, since any theme from prior to January, likely has the bad version (e.g., Newspaper 3.9.2 has the hackable version!). Also some themes on Themeforest and Envato (et al) have NOT been updated since January, and may be semi abandonware but are still being sold, with the bad version RIGHT NOW. So, they needed to do something about that issue, as people were buying themes and having their site(s) hacked pretty quick (another reason to use some form of comment removal to hide the versions of apps from your site header file!).
In fact, I know two themes got booted from my “purchase” line up of themes, which had not been updated in a long time, this month.
I tweeted about this, too and they tweeted back to clarify which versions were vulnerable. So, Themepunch has been on this pretty seriously. Similarly YOAST hired a security firm to audit their plugins, also. I think this may become a trend.
There are actually websites now which list all the current vulnerabilities in WordPress and plugins, which is very nice. I don’t check it all the time, but I do once in awhile out of curiosity.
eg
http://www.cvedetails.com/vulnerability-list/vendor_id-2337/product_id-4096/Wordpress-Wordpress.html
Or, subscribe to the SECURI Blog which usually catches stuff like the big flaw in ALL IN ONE SEO back in May.
http://blog.sucuri.net/category/wordpress
XMLRPC is often an issue which is why I do things to disable it.
But security is a whole different discussion. 🙂
