305 readers
The release of WordPress 2.8.2 has been announced. This was a relatively unexpected release, however it fixes a cross site scripting (XSS) vulnerability due to comment author URLs not being fully sanitized. This could then cause you to be directed to another site from your admin panel.
I’ve been reading on Twitter that people
305 readers
WordPress 2.8.3 was just released, just a couple weeks after the last one. This is a security update, so it’s highly recommended you upgrade immediately.
What exactly is fixed? According to Ryan Boren, some things that were supposed to be fixed in 2.8.2, as he “missed some places when fixing the privilege escalation issues.”
No
-
2498 readersUsers are advised that WordPress 3.0.3 has just been released and is a security update. This release fixes issues in the XML-RPC remote publishing interface. This release fixes issues in the remote publishing interface, which under certain circumstances allowed Author- and Contributor-level users to improperly edit, publish, or delete posts. If you have remote publishing
4841 readersAre you interested in trying out the automatic upgrade from WordPress MU 2.9.2 to WordPress 3.0 before WordPress 3.0 is released? Currently, WordPress 3.0 is at RC1 and it may be another two weeks or more before it 3.0 is officially released. Upgrading a WordPress MU install to the WordPress 3.0 RC with the built
-
3155 readersThe second beta of WordPress 3.1 has been released for your testing enjoyment. As before, you should probably avoid using this on a live site, and make sure to backup your files and database before upgrading. There are still a few known issues, but if you find any more, please feel free to discuss them
-
3300 readersThomas Mackenzie alerted us to a problem where logged in users can peek at trashed posts belonging to other authors. If you have untrusted users signed up on your blog and sensitive posts in the trash, you should upgrade to 2.9.2. As always, you can visit the Tools->Upgrade menu to upgrade.
2405 readersOur iThemes developer Chris Jean just did a blog post about WordPress 3.0 being released that has some good information about this blockbuster release for WP.
It’s one of the most highly anticipated releases yet … with custom menus, custom post types, and the WPMU now Multi-Site merge.
We’re very pleased to see Chris Jean’s name
-
0 readersIn case you haven’t noticed it yet in your WordPress dashboard, it looks like WordPress 2.8 has officially been released! Don’t forget if you are currently using WordPress 2.7 or 2.7.1, you can use the one-click upgrade feature built into WordPress to upgrade!
The changes from WordPress 2.7 aren’t as noticable as they were from 2.6
-
6208 readersWordPress 3.1.2 is now available and is a security release for all previous WordPress versions. This release addresses a vulnerability that allowed Contributor-level users to improperly publish posts. The issue was discovered by a member of our security team, WordPress developer Andrew Nacin, with Benjamin Balter. We suggest you update to 3.1.2 promptly, especially if
307 readers
As predicted, WordPress 2.8.4 has been released. No surprise here, after news about the admin password reset “exploit” issue surfaced yesterday. Yeah, there’s some arguments over whether it’s a security issue or not, but it can be pretty annoying if you get hit by it.
It’s highly recommended you upgrade immediately. This is