WordPress Breaks My Heart, Wants Me To Upgrade Again (2.8.6)
Its been less than a month since the last upgrade, and WordPress is asking the faithful to upgrade yet again.
(WordPress Development) 2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges. If you have untrusted authors on your blog, upgrading to 2.8.6 is recommended.
The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch. The second problem, discovered by Dawid Golunski, is an issue with sanitizing uploaded file names that can be exploited in certain Apache configurations. Thanks to Benjamin and Dawid for finding and reporting these.
See Also
Since this is related to security issues, it is recommended that WP fans upgrade ASAP–unless they desire their blog to be haunted by hackers.
Darnell Clayton is a geek who discovered blogging long before he heard of the word "blog" (he called them "web journals" then). When he is not tweeting, friendfeeding, or blogging about space, he enjoys running, reading and describing himself in third person.
Thank goodness for one-click upgrades! :)
Right, Andy! Since it’s so gd simple to upgrade now, I wouldn’t mind if there was a new update every week.
I guess I don’t understand why this post is titled, “WordPress Breaks My Heart,” though. I’m *glad* that they’re on top of security fixes like this …
We’ll break your heart, but not your blog.
Thanks Matt! ;-)
@DVG: Its not my blog I’m worried about, its the plugins that go with it. ;-) Fortunately all of them survived, so I don’t have to worry about my heart being broken again. ;-)