Now Reading
WordPress Breaks My Heart, Wants Me To Upgrade Again (2.8.6)

WordPress Breaks My Heart, Wants Me To Upgrade Again (2.8.6)

wordpress-logo

Its been less than a month since the last upgrade, and WordPress is asking the faithful to upgrade yet again.

(WordPress Development) 2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges. If you have untrusted authors on your blog, upgrading to 2.8.6 is recommended.

The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch. The second problem, discovered by Dawid Golunski, is an issue with sanitizing uploaded file names that can be exploited in certain Apache configurations. Thanks to Benjamin and Dawid for finding and reporting these.

See Also
ada and wcag compliance

Since this is related to security issues, it is recommended that WP fans upgrade ASAP–unless they desire their blog to be haunted by hackers.

View Comments (4)
Scroll To Top