Ok I’ve been busy lately (by lately I mean since 2.2 came out). I got a note a while ago from a friend about a problem with my RSS feed - didn’t think much about it. Then today I got an email from another friend who is trying our firefox 3 - it has a plugin that warns you when you visit a site that has malware. Apparently, my site is listed as a malware site…..
It turns out there was a hole in WordPress at some point that let them inject javascript and whatnot into the posts. They were hiding a bunch of it - but it showed up in the RSS.
I think I’ve cleaned out the bad posts (If you see one let me know), I’ve cleared out the back log of comments (all 25K of them), and updated to 2.5.1 - which is the latest and greatest - oh and it has security fixes for 2.5 (just released recently).
The only annoying thing is that every time I do this I have to deal with putting back in my patches to WordPress. I’m going to to give git a whril on this problem to see if it helps.
Also I noticed that some people are having problems with Postie on 2.5.x - I didn’t notice because I wasn’t running 2.5 - but since I am now - I’ll be fixing whatever the main problem is since I still need Postie to work.