Blogging Fool

15 Nov, 2009

WordPress Posts Yet Another Security Update in Advance of 2.9

Posted by: Blogging Fool In: Blogging Tips|Security

Automattic just won’t let anything slide, now will its community of developers and users. The fourth in a series of .1 updates created to address possible security issues that could be exploited by malicious users or even registered contributors, WP 2.8.5 includes the following key changes:

* A fix for the Trackback Denial-of-Service attack that is currently being seen.
* Removal of areas within the code where php code in variables was evaluated.
* Switched the file upload functionality to be whitelisted for all users including Admins.
* Retiring of the two importers of Tag data from old plugins.

The update for custom WordPress installation can be easily applied from the admin panel and it is strongly recommended that you do. When last we check, there was even a 2.8.6 release cooking. We may have to wait just a little longer for 2.9 but at least we will sleep more soundly knowing that the doors have been locked.

Share

No Responses to "WordPress Posts Yet Another Security Update in Advance of 2.9"

Comment Form


  • Blogging Fool: Ideally, yes.
  • Abigail: Thank you, I am a newbie at all this, that description of anchor text is great. Thank you. Do you use your keywords that you want to rank for, as an
  • Blogging Fool: A blog is a content management system "CMS" whose etymology is the longer term "web log" - developed by a man who wanted to create a journal of his in

About

Blogging Fool has been running internet communities since the days of Lynx, Veronica and gopher but only really understood the heart and soul of blogging as late as 2008. He has been invited to speak about emerging media strategies at conferences across North America.

Sign up for my private newsletter!

Name:
E-mail address:
Blogging Fool
Subscribe

Twitter links powered by Tweet This v1.8.3, a WordPress plugin for Twitter.