Heads up to all WordPress users! A new security update – WordPress 3.1.2 was just released a few hours ago. This security release addresses a vulnerability allowing Contributor-level users to improperly publish posts so everyone is strongly advised to update to this latest version especially if user registration is enabled on your WordPress-powered blog or [...]
Continue reading...Tuesday, April 5, 2011
A few hours ago, Ryan Boren announced via the official WordPress blog the availability of WordPress 3.1.1. This update is a maintenance and security release that contains about thirty patches/fixes to issues found on the 3.1 version like security hardening to media uploads, performance improvements, fixes for IIS6 support, fixes for taxonomy and PATHINFO (/index.php/) [...]
Continue reading...Wednesday, February 9, 2011
Two days ago, the WordPress dev team released WordPress 3.0.5 which is a security hardening update that includes security enhancements like improved security of any plugins that didn’t properly leverage security API, additional in-depth defense against vulnerabilities, fix for a information disclosure issue that could’ve allowed author-level users to view content of drafts & private [...]
Continue reading...Thursday, December 30, 2010
The WordPress dev team has released the WordPress 3.0.4 security update to fix a core security bug in the HTML sanitation library. This particular version or release is classified as “critical” so all self-hosted WordPress users are advised to update/upgrade their WordPress installation ASAP! Here’s an excerpt of the official announcement from the WordPress blog: [...]
Continue reading...Thursday, December 9, 2010
Just a week after they released the WordPress 3.0.2 security update, the WordPress dev team has released another security update early this morning – WordPress 3.0.3. This security update is mandatory for all previous versions of WordPress. WordPress 3.0.3 fixes issues found in the remote publishing interface that in certain situations could allow Author and [...]
Continue reading...Wednesday, December 1, 2010
Just a few minutes ago, the WordPress dev team released WordPress 3.0.2, a security release or security update that is mandatory for all self-hosted WordPress blogs. WordPress 3.0.2 addresses a moderate security issue that could allow a malicious user with Author-level privileges to gain further access to the whole site/blog. This version also fixes several [...]
Continue reading...Thursday, November 12, 2009
Just as I finished publishing my previous post, I saw the notification that WordPress 2.8.6 security release is now available for download. Here’s what the official WordPress blog has to say about this new release: 2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges. If you [...]
Continue reading...Tuesday, August 11, 2009
Another heads up for all WordPress users. The WordPress dev team just released another security update WordPress 2.8.4 to fix a vulnerability discovered yesterday. Yesterday a vulnerability was discovered: a specially crafted URL could be requested that would allow an attacker to bypass a security check to verify a user requested a password reset. As [...]
Continue reading...
Wednesday, April 27, 2011
2 Comments