09-04-2014, 10:45 AM
If you have any wordpress websites with Revolution Slider on it, this is a must read!
It is URGENT that you update rev slide RIGHT NOW!
There is a major security issue that is easy to exploit that requires an update to the plugin. Essentially all anyone has to do is enter the following url on a vulnerable website:
http://DOMAIN-HERE/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php
That will download the wp-config.php file which includes your database credentials. I checked it on some of my sites and found several vulnerable. It is urgent that you update the plugin.
Steps to patch:
1. Download the latest version, here is a link straight from the developer
2. Log into the wordpress website that has the plugin installed
3. Click on the settings for the plugin and scroll to the very bottom
4. There will be a button on the right to update the plugin
5. Self explanatory from there
Do not delete the plugin and reupload because all your sliders will be lost.
After you download the latest from the link above, you have to unzip the file and in there you will see the plugin and all the documentation.
Let's all keep this bumped for a few days so as many in the community will see it.
It is URGENT that you update rev slide RIGHT NOW!
There is a major security issue that is easy to exploit that requires an update to the plugin. Essentially all anyone has to do is enter the following url on a vulnerable website:
http://DOMAIN-HERE/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php
That will download the wp-config.php file which includes your database credentials. I checked it on some of my sites and found several vulnerable. It is urgent that you update the plugin.
Steps to patch:
1. Download the latest version, here is a link straight from the developer
Code:
https://www.dropbox.com/s/2m9taf90gheka5d/codecanyon-2751380-slider-revolution-responsive-wordpress-plugin.zip?dl=0
3. Click on the settings for the plugin and scroll to the very bottom
4. There will be a button on the right to update the plugin
5. Self explanatory from there
Do not delete the plugin and reupload because all your sliders will be lost.
After you download the latest from the link above, you have to unzip the file and in there you will see the plugin and all the documentation.
Let's all keep this bumped for a few days so as many in the community will see it.