WordPress Breaks My Heart, Wants Me To Upgrade Again (2.8.6)


Its been less than a month since the last upgrade, and WordPress is asking the faithful to upgrade yet again.

(WordPress Development) 2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges. If you have untrusted authors on your blog, upgrading to 2.8.6 is recommended.

The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch. The second problem, discovered by Dawid Golunski, is an issue with sanitizing uploaded file names that can be exploited in certain Apache configurations. Thanks to Benjamin and Dawid for finding and reporting these.

Since this is related to security issues, it is recommended that WP fans upgrade ASAP–unless they desire their blog to be haunted by hackers.

Like & Share this Article


  1. says

    Right, Andy! Since it’s so gd simple to upgrade now, I wouldn’t mind if there was a new update every week.

    I guess I don’t understand why this post is titled, “WordPress Breaks My Heart,” though. I’m *glad* that they’re on top of security fixes like this …

  2. says

    Thanks Matt! ;-)

    @DVG: Its not my blog I’m worried about, its the plugins that go with it. ;-) Fortunately all of them survived, so I don’t have to worry about my heart being broken again. ;-)

Leave a Reply

Your email address will not be published. Required fields are marked *