I recently upgraded to WordPress 2.5 – and in the process of doing so, I noticed something funky with my older 2.3.3 installs claiming to be 2.5 already. I thought it was odd – but didn’t immediately come across anyone having reported strangeness here and so I just ignored it.
Now that 2.5.1 is out, I thought I’d go upgrade again. Well, after the upgrade I was still having the dashboard tell me that I needed to upgrade. Odd. This time a web search did uncover information that was relevant.
Details on the wp-info.txt exploit are interesting. It seems to me that several problems are being lumped into the one discussion, but I found some helpful advice to help clean things up from the links provided there.
Symptoms:
- Presence of wp-info.txt
- Displayed version changed without upgrading.
- Database modifications
- New files ending in _new, _old, .pngg, .jpgg, .giff appearing inside writable directory