PDA

View Full Version : xmlrpc.php


krisleech
07-18-2005, 02:53 PM
Has anyone fixed the xmlrpc.php issue in wordpress?

lisch
07-18-2005, 03:17 PM
My understanding is that version 1.5.1.3 fixes xmlrpc vulnerabilities. See the WordPress development blog (http://wordpress.org/development/2005/06/wordpress-1513) for more information (although they don't give all that much info about the vulnerability).

SteveYoung
07-18-2005, 04:41 PM
I am working on 3 active sites right now to solve the issue.

My guess is that without xmlrpc.php running xml is the only loss. FQ has disabled and the site still functions. We do not push xml and have removed it from the presentation portion of our wordpress implimentations.

I will update here what works for me.

TVB
07-18-2005, 06:01 PM
If you are running a wordpress version 1.5 or above, the update is easy. Just delete some files and upload the new ones. There are not any scripts to run.

http://codex.wordpress.org/Upgrading_WordPress#Upgrade_1.5.1.2_to_1.5.1.3

Unfortunately, I also had to do a fix on phpMyFAQ which turned into a big problem. I eventually got it done, but for some reason, it turned into a real hassle. It was likely something I did.:blush:

SteveYoung
07-18-2005, 06:08 PM
I have one I am not using. Delete the file.
I have one running 1.2 (need to upgrade)
I have 3 running 1.5 (need to upgrade)
Doing full backups now before the upgrades (both site and sql files)
Just in case!

SteveYoung
07-18-2005, 09:13 PM
Delete the file worked fine for the one I do not use.
The 1.2 upgrade to 1.5.1.3 needs to wait for the weekend, I will delete the file till then.
I have upgraded the 1.5's to 1.5.1.3 easy upgrade, just took time to backup.
Thanks FQ for the email on the problem so we could fix it. :yeah:

One of these blogs www.NHcafe.org has become very popular, it would have been very bad to have had a security issue.

Steve