The conjuring discussion regarding security checking on the WordPress wp-hackers mailing list and my subsequent testing have revealed a serious security flaw in Liberated WordPress 1.5.2, the software that runs this blog.
The flaw allows anyone I trust to post drafts, to make a draft post containing images with appropriately forged source hrefs, to subsequently destroy the entire contents of the blog when an administrator views the draft, with no interaction required.
In other words, an automatic nuclear bomb.
Fortunately, the only person entrusted to write posts on this blog is me, so unless I decide to nuke myself, I’m pretty safe. On the other hand, knowing my blog could vapourise at any time gives me the willies. I can’t wait for someone else to issue a repair.
I’m going to have to fix this one all by myself.
(more…)