Its been less than a month since the last upgrade, and WordPress is asking the faithful to upgrade yet again.
(WordPress Development) 2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges. If you have untrusted authors on your blog, upgrading to 2.8.6 is recommended.
The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch. The second problem, discovered by Dawid Golunski, is an issue with sanitizing uploaded file names that can be exploited in certain Apache configurations. Thanks to Benjamin and Dawid for finding and reporting these.
Since this is related to security issues, it is recommended that WP fans upgrade ASAP–unless they desire their blog to be haunted by hackers.
Author: Darnell Clayton
Darnell Clayton is a geek who discovered blogging long before he heard of the word “blog” (he called them “web journals” then).
When he is not tweeting, friendfeeding, or blogging about space, he enjoys running, reading and describing himself in third person.