HNHacker News
TopNewBestAskShowJobs

coenjacobs

2 karma · joined April 12, 2012

submissionscomments
coenjacobs··on Remote exploit found in all WooThemes
No, the update pops up within your WordPress admin panel in case you are using one of our themes. Secondary download - with the link I provided - is available because our site was hacked last week: http://www.woothemes.com/2012/04/were-alive-and-kicking/ We only use that download link temporarily to be able to provide the update to our users.
coenjacobs··on Remote exploit found in all WooThemes
No, the update pops up within your WordPress admin panel in case you are using one of the WooThemes themes. That download is behind a login, this zip is publicly available for all people that didn't believe it was already fixed.
coenjacobs··on Remote exploit found in all WooThemes
Not related at all. See my reply here: http://news.ycombinator.com/item?id=3905337
coenjacobs··on Remote exploit found in all WooThemes
Not related at all and the WooFramework has been updated days before all this: http://cl.ly/3S2o1z380L3i1D44443A

For the people not yet on the latest WooFramework version: You can download the latest version of WooFramework here: http://cl.ly/2a3j1m351C3u2i0t122j (it is 5.3.10)

Do you know how to manually update the framework? This zip file unzips to a "framework" folder, you need to replace to contents of the "functions" folder of your theme. Obviously make a backup of everything before you start.

This exploit is fixed in the latest two stable builds and should have been reported to us (WooThemes team) in the first place. Wonder if this guy has ever heard of the concept of responsible disclosure...