Host gator Webhosting
  Share

Wordpress 2.8.6 Released Multi author Security update

by Harsh Agrawal on November 13, 2009

in Wordpress

Today when I logged into my Wordpress dashboard I will kind of surprised with the latest release of wordpress 2.8.6. I was expecting to see wordpress 2.9 soon. But this new update come as a surprise for me.

I went to official wordpress blog and realize, this update has been made to prevent two security vulnerabilities, which can be exploited by registered author of your blog, who have posting permission.

According to official announcement

The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch.  The second problem, discovered by Dawid Golunski, is an issue with sanitizing uploaded file names that can be exploited in certain Apache configurations.

So like always sound advice, update your wordpress blog ASAP. Specially if you have multi-author blog. Don’t forget to take backup of your wordpress blog database.

Enter your email address:

Related posts:

  1. Wordpress 2.8.4 Released due to a Serious Security Risk
  2. Register plus Wordpress plugin for Multi Author blog
  3. Status Notifier Wordpress revenue sharing blog plugin
  4. Wordpress Users Photo Plugin : Gravatar Alternative for Wordpress Membership website
  5. Wordpress 2.8.1 Beta Released Lots of bugs fixed


{ 4 comments… read them below or add one }

1 George Serradinho November 13, 2009 at 02:28

Thanks for this, I was logged on and never saw any message. I will have to update as I have other authors who have started to post.

Reply

2 IndianCashMaker November 13, 2009 at 18:17

i will think before i upgrade…last time i made a mess of it….is it mandatory??

Reply

3 Harsh Agrawal November 13, 2009 at 20:16

If you have multi author blog, it is.. Else you can ignore it for now.

Reply

4 Shahab November 13, 2009 at 23:41

WordPress Automatic upgrade does everything so smoothly that there is no reason to worry at all :)

Reply

Leave a Comment

Previous post: Change Feedburner Email Delivery Title to Make it more Effective

Next post: CSS Injection in Google Docs Forms