Joining the news of the Heartbleed vulnerability that affects much of the internet, and a security update for WordPress itself, now comes the news that there is a critical security update for the Jetpack WordPress plugin.
Jetpack 2.9.3 contains a fix for a bug which allows an attacker to bypass access controls and publish posts, which could be combined with other attacks to escalate access. It’s existed since the release of Jetpack 1.9 in October 2012, and as yet there is no evidence of it being used in the wild.

However, now it has been made public, you need to make sure your site is updated asap – the team behind Jetpack have been working with hosting and network providers to reduce the problem, and have made updated releases for all 11 vulnerable versions of Jetpack from 1.94 through to 2.9.3.
So if you’re running Jetpack on one or more of your sites, make sure you’re either updating it now through your WordPress dashboard, or visit the Jetpack site to manually grab the updated releases and install the appropriate one for your website.
