WordPress Breaks My Heart, Wants Me To Upgrade Again (2.8.6)

Filed as News on November 13, 2009 3:16 am

Repost This

wordpress-logo

Its been less than a month since the last upgrade, and WordPress is asking the faithful to upgrade yet again.

(WordPress Development) 2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges. If you have untrusted authors on your blog, upgrading to 2.8.6 is recommended.

The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch. The second problem, discovered by Dawid Golunski, is an issue with sanitizing uploaded file names that can be exploited in certain Apache configurations. Thanks to Benjamin and Dawid for finding and reporting these.

Since this is related to security issues, it is recommended that WP fans upgrade ASAP–unless they desire their blog to be haunted by hackers.

This post was written by

You can visit the for a short bio, more posts, and other information about the author.

Submissions & Subscriptions

Submit the post to Reddit, StumbleUpon, Digg or Del.icio.us.

Did you like it? Then subscribe to our RSS feed!



  1. By Andy Merrett posted on November 13, 2009 at 10:56 am
    Want an avatar? Get a gravatar! • You can link to this comment

    Thank goodness for one-click upgrades! :)

    Reply

  2. By dvg posted on November 13, 2009 at 5:26 pm
    Want an avatar? Get a gravatar! • You can link to this comment

    Right, Andy! Since it’s so gd simple to upgrade now, I wouldn’t mind if there was a new update every week.

    I guess I don’t understand why this post is titled, “WordPress Breaks My Heart,” though. I’m *glad* that they’re on top of security fixes like this …

    Reply

  3. By Matt posted on November 13, 2009 at 11:04 pm
    Want an avatar? Get a gravatar! • You can link to this comment

    We’ll break your heart, but not your blog.

    Reply

  4. By Darnell Clayton posted on November 18, 2009 at 11:24 pm
    Want an avatar? Get a gravatar! • You can link to this comment

    Thanks Matt! ;-)

    @DVG: Its not my blog I’m worried about, its the plugins that go with it. ;-) Fortunately all of them survived, so I don’t have to worry about my heart being broken again. ;-)

    Reply

    Your words are your own, so be nice and helpful if you can. If this is the first time you're posting a comment, it might go into moderation. Don't worry, it's not lost, so there's no need to repost it! We accept clean XHTML in comments, but don't overdo it please.

    Current day month ye@r *