Posted on 26 November, 2008 By Kim Woodbridge 8 Comments

WordPress 2.6.5 - Security and Bug Fix Released

WM2006 Fan Fest Stuttgart - Security (by Heraklit)

Um … meh … great.

WordPress 2.6.5 has been released, which is a security upgrade.

I did not expect this at all as WordPress 2.7 is supposed to be released very soon.

And what is in this security release? Well, there is one security fix and three bug fixes.

 

The security issue is an XSS exploit discovered by Jeremias Reith that fortunately only affects IP-based virtual servers running on Apache 2.x. If you are interested only in the security fix, copy wp-includes/feed.php and wp-includes/version.php from the 2.6.5 release package.

2.6.5 contains three other small fixes in addition to the XSS fix. The first prevents accidentally saving post meta information to a revision. The second prevents XML-RPC from fetching incorrect post types. The third adds some user ID sanitization during bulk delete requests. For a list of changed files, consult the full changeset between 2.6.3 and 2.6.5.

Got that? Good. Me neither.

Now what I think it the most important part of this is where is 2.6.4?

Well, a fake WordPress site released version 2.6.4 that contained code that opens up the entire WordPress installation. There is no version 2.6.4. If you are running it, your WordPress was hacked. Instructions for clearing this up are available at Viper007Bond.

As always, I recommend upgrading to 2.6.5. Enjoy! I know how you all love the upgrades.

***Update: This release can be updated with 5 files rather than having to upgrade the entire installation.

  1. /wp-admin/users.php
  2. /wp-includes/feed.php
  3. /wp-includes/post.php
  4. /wp-includes/version.php
  5. xmlrpc.php

photo credit: Heraklit


Related Posts:
  • (Anti) Social-Lists 5/10/09
  • WordPress: Security Update 2.6.3 Released
  • WordPress 2.8 Upgrade Issues and Recommendations
  • 5 Most Popular (Anti) Social Articles Written This Year
  • WordPress Login Security
  • Posted In : WordPress Tips
    If you enjoyed this post, please subscribe to my RSS Feed

    [Post to Twitter]   [Post to Delicious]   [Post to StumbleUpon]

    8 Responses to “WordPress 2.6.5 - Security and Bug Fix Released”

    Leave a Comment
    You may use: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> .


    Additional comments powered by BackType

    Recent Comments

      • Davina: Hi Kim. Although I don't know all of these bloggers, I do know some and they are definitely great supporters. So this of...
      • Fábio N Sarmento: Do you have any idea how can i exclude a certain category, when the TT do the "new blog post" update, i want it show al...
      • Kikolani: Those are some good, patriotic themes that could be modified to work year round. Thanks for the round up! ~ Kristi...
      • Jannie Funster: Kim, that is just the sweetest shout-out ever. I guess no good deed with you goes unappreciaated, and in such a public ...
      • Kim Woodbridge: Hi - Is this for a fan page or a profile page? On a fan page go to Edit Page. In the list of Applications click on the ...
      • Kim Woodbridge: Hi Valerie - Sometimes when I'm really tired I just sit here and mindlessly click around the internet and the same thing...
      • Kim Woodbridge: Hi Patricia, Thank you so much for the kind words - I really appreciate it and you comment has made my day :-) Hav...
      • Kim Woodbridge: Hi John - Jeff is wonderful and a really nice person. They already have some great stuff on the new site and I can't wa...