Posted on 26 November, 2008 By Kim Woodbridge 8 Comments

WordPress 2.6.5 – Security and Bug Fix Released

 
Share

WM2006 Fan Fest Stuttgart - Security (by Heraklit)

Um … meh … great.

WordPress 2.6.5 has been released, which is a security upgrade.

I did not expect this at all as WordPress 2.7 is supposed to be released very soon.

And what is in this security release? Well, there is one security fix and three bug fixes.

 

The security issue is an XSS exploit discovered by Jeremias Reith that fortunately only affects IP-based virtual servers running on Apache 2.x. If you are interested only in the security fix, copy wp-includes/feed.php and wp-includes/version.php from the 2.6.5 release package.

2.6.5 contains three other small fixes in addition to the XSS fix. The first prevents accidentally saving post meta information to a revision. The second prevents XML-RPC from fetching incorrect post types. The third adds some user ID sanitization during bulk delete requests. For a list of changed files, consult the full changeset between 2.6.3 and 2.6.5.

Got that? Good. Me neither.

Now what I think it the most important part of this is where is 2.6.4?

Well, a fake WordPress site released version 2.6.4 that contained code that opens up the entire WordPress installation. There is no version 2.6.4. If you are running it, your WordPress was hacked. Instructions for clearing this up are available at Viper007Bond.

As always, I recommend upgrading to 2.6.5. Enjoy! I know how you all love the upgrades.

***Update: This release can be updated with 5 files rather than having to upgrade the entire installation.

  1. /wp-admin/users.php
  2. /wp-includes/feed.php
  3. /wp-includes/post.php
  4. /wp-includes/version.php
  5. xmlrpc.php

photo credit: Heraklit


Related Posts:
  • WordPress 2.8.2 Released – Say What? A Security Release
  • WordPress 2.8.1 Released
  • (Anti) Social-Lists 5/10/09
  • WordPress: Security Update 2.6.3 Released
  • WordPress 2.9.2 Released: Security Release for Trash
  • Posted In : WordPress Tips
    If you enjoyed this post, please subscribe to my RSS Feed. You can also connect with my Facebook page or follow me on Twitter.



    8 Responses to “WordPress 2.6.5 – Security and Bug Fix Released”

    Leave a Comment
    You may use: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> .

    CommentLuv Enabled

    Recent Comments

      • Ari Herzog: Agreed on the updates/inbox snafu. I rarely see page updates and I know where they are! .-= Ari Herzog´s last blog .....
      • jayson: Kim, Love the themes. I am looking to update the theme on my site to something more appropriate. My site is all abou...
      • vered: "I wish more people would use this. I think it’s silly when I get updates for things occuring in Kansas and California –...
      • Dennis Edell @ Direct Sales Marketing: I was speaking generally, not specifically this month. how exactly do you work things? .-= Dennis Edell @ Direct Sales M...
      • Lucy Beer: Unfortunately I think next to no-one actually sees those "Updates". They're buried in a subsection of the inbox and I do...
      • Kim Woodbridge: Hi Marbella - Thanks! I had a great time....
      • Kim Woodbridge: Hi Julie - I'll probably try kayaking again next summer but I don't know if I will become much of a kayaker - I had a di...
      • Kim Woodbridge: Hi Vered - If you ever get the chance, you should go. It's like a different world - it's so quiet and peaceful....

    About

    Kim Woodbridge is an accomplished Information and Technical Consultant specializing in the entire implementation of a WordPress based website including installation, theme design, upgrades, unique customizations and ongoing site maintenance.

    Wordpress Services

    • Installation, upgrades and maintenance
    • Conversion of existing html and css templates
    • Theme and plugin recommendations
    • CSS customizations
    • Troubleshooting and tweaks for unique situations
    • Customization for individual blogging goals and needs
    • Training and advice