Releases

WordPress 2.8.6 Security Release

2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges.  If you have untrusted authors on your blog, upgrading to 2.8.6 is recommended. The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch.  The second problem, discovered by Dawid Golunski, is an issue [...]

Read more...

Be the first to comment - What do you think?  Posted by 18916 - November 12, 2009 at 1:17 pm

Categories: Releases, Security   Tags:

WordPress 2.8.5: Hardening Release

As you know over the past couple of months we have been working on the new features for WordPress 2.9. We have also been working on trying to make WordPress as secure as possible and during this process we have identified a number of security hardening changes that we thought were worth back-porting to the [...]

Read more...

Be the first to comment - What do you think?  Posted by 18916 - October 20, 2009 at 5:30 pm

Categories: Releases, Security   Tags:

WordPress 2.8.4: Security Release

Yesterday a vulnerability was discovered: a specially crafted URL could be requested that would allow an attacker to bypass a security check to verify a user requested a password reset. As a result, the first account without a key in the database (usually the admin account) would have its password reset and a new password [...]

Read more...

Be the first to comment - What do you think?  Posted by 18916 - August 11, 2009 at 7:41 pm

Categories: Releases, Security   Tags:

WordPress 2.8.3 Security Release

Unfortunately, I missed some places when fixing the privilege escalation issues for 2.8.1.  Luckily, the entire WordPress community has our backs.  Several folks in the community dug deeper and discovered areas that were overlooked.  With their help, the remaining issues are fixed in 2.8.3.  Since this is a security release, upgrading is highly recommended.  Download [...]

Read more...

Be the first to comment - What do you think?  Posted by 18916 - August 3, 2009 at 9:30 am

Categories: Releases   Tags:

WordPress 2.8.2

WordPress 2.8.2 fixes an XSS vulnerability. Comment author URLs were not fully sanitized when displayed in the admin. This could be exploited to redirect you away from the admin to another site.  Download 2.8.2 or automatically upgrade from the Tools->Upgrade page of your blog’s admin.

Read more...

Be the first to comment - What do you think?  Posted by 18916 - July 19, 2009 at 11:35 pm

Categories: Releases   Tags:

Next Page »