Security

WordPress 2.8.6 Security Release

2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges.  If you have untrusted authors on your blog, upgrading to 2.8.6 is recommended. The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch.  The second problem, discovered by Dawid Golunski, is an issue [...]

Read more...

Be the first to comment - What do you think?  Posted by 18916 - November 12, 2009 at 1:17 pm

Categories: Releases, Security   Tags:

WordPress 2.8.5: Hardening Release

As you know over the past couple of months we have been working on the new features for WordPress 2.9. We have also been working on trying to make WordPress as secure as possible and during this process we have identified a number of security hardening changes that we thought were worth back-porting to the [...]

Read more...

Be the first to comment - What do you think?  Posted by 18916 - October 20, 2009 at 5:30 pm

Categories: Releases, Security   Tags:

How to Keep WordPress Secure

A stitch in time saves nine. I couldn’t sew my way out of a bag, but it’s true advice for bloggers as well — a little bit of work on an upgrade now saves a lot of work fixing something later. Right now there is a worm making its way around old, unpatched versions of WordPress. [...]

Read more...

Be the first to comment - What do you think?  Posted by 18916 - September 5, 2009 at 1:22 pm

Categories: Security   Tags:

WordPress 2.8.4: Security Release

Yesterday a vulnerability was discovered: a specially crafted URL could be requested that would allow an attacker to bypass a security check to verify a user requested a password reset. As a result, the first account without a key in the database (usually the admin account) would have its password reset and a new password [...]

Read more...

Be the first to comment - What do you think?  Posted by 18916 - August 11, 2009 at 7:41 pm

Categories: Releases, Security   Tags:

The WordPress 2.0.x Legacy Branch is Deprecated

The WordPress team had initially committed to maintaining the WordPress 2.0.x legacy branch until 2010. Unfortunately, we bit off more than we could chew—the 2.0.x branch is now retired and deprecated, a few months shy of 2010. Many of the security improvements to the new versions of WordPress in the last couple of years were complete [...]

Read more...

1 comment - What do you think?  Posted by 18916 - July 29, 2009 at 7:07 pm

Categories: Security   Tags: