Hackers have compromised several servers that support WordPress and may have obtained source code, according to the founding developer of Automattic, the company behind the popular blogging platform. He wrote on the WordPress blog that Automattic has been reviewing log records to determine how much information was exposed and re-evaluating "avenues to gain access." "We presume our source code was exposed and copied," he wrote. "While much of our code is open source, there are sensitive bits of our and our partners’ code. Beyond that, however, it appears information disclosed was limited." He wrote the company had no specific advice for WordPress users besides using strong passwords, and not using the same password for multiple sites. In the comment section of the blog post, a user asked if WordPress stores passwords in plain text or stores hashes of passwords. The founding developer wrote WordPress uses the Portable PHP password hashing framework. Source:

on Apr 15, 2011

This is the second time in 6 months that WordPress has been compromised.  One of our web sites was among the victims last fall when they gained root access to some servers.

