• 20th November 2009 - By The WP Warrior

    Another Wordpress update has been released.  Version 2.8.6 was released on November 12 and fixes two security problems, which can be used by registered, logged in users.

    If you’re running a multi author wordpress blog, you really should apply this update.

    Quoting from the Wordpress Release Notes:

    2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges.  If you have untrusted authors on your blog, upgrading to 2.8.6 is recommended.

    The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch.  The second problem, discovered by Dawid Golunski, is an issue with sanitizing uploaded file names that can be exploited in certain Apache configurations. Thanks to Benjamin and Dawid for finding and reporting these.

    To update to version 2.8.6, you can log in to your Wordpress dashboard and click on the Update Now button.

    Morgan Leetham runs and manages several WP blogs and has a lot of fun designing and building themes.

  • Leave a Reply

    CommentLuv Enabled
     characters available