possible exploit in tinymce js
-
Hi, everyone, i’ve been using wordpress for almost a year now to run my magazine site and soon after I upgraded to 2.0 the other day and a day or so later a bot used one of the javascripts to insert an exploit (the wmf exploit that is on the news) to every php and html file in my account. It then began trying to serve the exploit to my visitors from a url that I won’t post because it is direct to the wmf file. I’m protected against it and the only way I even notice it is anti-vir kept giving me warnings. I have screenshots of the warnings. My site is hosted at powweb and they kept turning off my wordpress database telling me it was abusing the system, so i restored a backup and that seemed to stop it, but when I went into wordpress to write a post and clicked the edit html button on the tinymce quicktags, it started all over again. Does anyone know if this is a possible exploit in tinymce js and has anyone else had this problem? How can I get rid of it? I deleted tinymce from my server, just in case.
thanks in advance for any help I may recieve.
The topic ‘possible exploit in tinymce js’ is closed to new replies.