Dev Blog: WordPress 2.8.6 Security Release

Find the latest vBulletin information about Dev Blog: WordPress 2.8.6 Security Release relating to Wordpress at The Staff Lounge. This was a vBulletin news entry posted 4 months ago. Dev Blog: WordPress 2.8.6 Security Release.




Dev Blog: WordPress 2.8.6 Security Release

Wordpress

2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges.  If you have untrusted authors on your blog, upgrading to 2.8.6 is recommended.

The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch.  The second problem, discovered by Dawid Golunski, is an issue with sanitizing uploaded file names that can be exploited in certain Apache configurations. Thanks to Benjamin and Dawid for finding and reporting these.

Get WordPress 2.8.6.


One Response to “Dev Blog: WordPress 2.8.6 Security Release”  

  1. 1 Keith Davis

    You were quick… 2.8.6 out already?

    It’s fantastic that the boys at wordpress are giving us the best protection possible with these updates, but 2.8.6?

    I’ve just upgraded to 2.8.5 and thought that my next upgrade would be 2.9… how wrong was I?

Leave a Reply



About This Entry

About This Entry
  • You’re currently reading “Dev Blog: WordPress 2.8.6 Security Release,” an entry on The Staff Lounge

  • Published at 11.12.09 / 8pm

Powered By

Living Off

Forums Powered By vBulletin Blog Powered By Wordpress Skin Designed By Binary Bonsai