WPtouch hacked

I logged into my WordPress installation, which is hosted with Amazon Web Services, and noticed a post from the WordPress team stating,

Earlier today the WordPress team noticed suspicious commits to several popular plugins (AddThis, WPtouch, and W3 Total Cache) containing cleverly disguised backdoors. We determined the commits were not from the authors, rolled them back, pushed updates to the plugins, and shut down access to the plugin repository while we looked for anything else unsavory.

I have WPtouch installed and I immediately deactivated the plugin until I could investigate any issues.

The developers of WPtouch, had this to say,

If you haven’t updated WPtouch in the last few days, then this issue will not have affected you. But we encourage anyone that is running WPtouch version 1.9.27 or 1.9.28 to update to version 1.9.29 immediately.

Luckily, I had not updated the plugin recently; however, little information has been published concerning the “suspicious commits” and for now I am taking a wait and see approach before updating and re-enabling WPtouch.

Lesson? Secure your source code repositories.

References:
http://wordpress.org/news/2011/06/passwords-reset/
http://www.bravenewcode.com/2011/06/important-security-update-wptouch-1-9/

Tags: , , ,

1 Response to "WPtouch hacked"

Leave a Comment