Posted on 22 July, 2009 By Kim Woodbridge 11 Comments

WordPress 2.8.2 Released – Say What? A Security Release

 
Share

Police - 1978 (by AndyWilson)

Oh look. A birthday gift from the WordPress folks to me.

WordPress 2.8.2 was released on July 20th and is a security fix

I didn’t notice this until tonight because I’ve been out of the loop, ignoring the news, and freaking out. I tried to take a day off, tried to celebrate another journey around the sun, and tried to deal with an extremely sick kid with a Foreigner (the band) style fever.

So, apparently there is a XSS vulnerability. I know, I know – the XSS stuff really gets to me too ;-)

But this is a bad bugaboo. The URL left by a commentator can be exploited to redirect you away from the WordPress admin to some nefarious, evil other site.

I shouldn’t joke – this is serious. If you are already running 2.8 or 2.8.1, upgrade as soon as possible. (Make backups first). If you are still running the WordPress 2.7 series, you may want to sit tight for a couple of days to see it 2.8.3 makes an appearance.

Enjoy! Oh – and remember my guide to upgrading WordPress manually is still a valuable resource. A self-processed upgrade “newbie” said he used it successfully for his first ever manual upgrade.

photo credit: AndyWilson


Related Posts:
  • WordPress 2.9.2 Released: Security Release for Trash
  • (Anti) Social-Lists 5/10/09
  • WordPress 2.6.5 – Security and Bug Fix Released
  • A WordPress Plugin that will Update URL’s and Links When Moving a Site
  • 8 WordPress Spring Cleaning Tips
  • Posted In : WordPress Tips
    If you enjoyed this post, please subscribe to my RSS Feed. You can also connect with my Facebook page or follow me on Twitter.



    11 Responses to “WordPress 2.8.2 Released – Say What? A Security Release”

    Leave a Comment
    You may use: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> .

    CommentLuv Enabled

    Recent Comments

      • Ari Herzog: Agreed on the updates/inbox snafu. I rarely see page updates and I know where they are! .-= Ari Herzog´s last blog .....
      • jayson: Kim, Love the themes. I am looking to update the theme on my site to something more appropriate. My site is all abou...
      • vered: "I wish more people would use this. I think it’s silly when I get updates for things occuring in Kansas and California –...
      • Dennis Edell @ Direct Sales Marketing: I was speaking generally, not specifically this month. how exactly do you work things? .-= Dennis Edell @ Direct Sales M...
      • Lucy Beer: Unfortunately I think next to no-one actually sees those "Updates". They're buried in a subsection of the inbox and I do...
      • Kim Woodbridge: Hi Marbella - Thanks! I had a great time....
      • Kim Woodbridge: Hi Julie - I'll probably try kayaking again next summer but I don't know if I will become much of a kayaker - I had a di...
      • Kim Woodbridge: Hi Vered - If you ever get the chance, you should go. It's like a different world - it's so quiet and peaceful....

    About

    Kim Woodbridge is an accomplished Information and Technical Consultant specializing in the entire implementation of a WordPress based website including installation, theme design, upgrades, unique customizations and ongoing site maintenance.

    Wordpress Services

    • Installation, upgrades and maintenance
    • Conversion of existing html and css templates
    • Theme and plugin recommendations
    • CSS customizations
    • Troubleshooting and tweaks for unique situations
    • Customization for individual blogging goals and needs
    • Training and advice