Posted on 22 July, 2009 By Kim Woodbridge 11 Comments

WordPress 2.8.2 Released – Say What? A Security Release

Police - 1978 (by AndyWilson)

Oh look. A birthday gift from the WordPress folks to me.

WordPress 2.8.2 was released on July 20th and is a security fix

I didn’t notice this until tonight because I’ve been out of the loop, ignoring the news, and freaking out. I tried to take a day off, tried to celebrate another journey around the sun, and tried to deal with an extremely sick kid with a Foreigner (the band) style fever.

So, apparently there is a XSS vulnerability. I know, I know – the XSS stuff really gets to me too ;-)

But this is a bad bugaboo. The URL left by a commentator can be exploited to redirect you away from the WordPress admin to some nefarious, evil other site.

I shouldn’t joke – this is serious. If you are already running 2.8 or 2.8.1, upgrade as soon as possible. (Make backups first). If you are still running the WordPress 2.7 series, you may want to sit tight for a couple of days to see it 2.8.3 makes an appearance.

Enjoy! Oh – and remember my guide to upgrading WordPress manually is still a valuable resource. A self-processed upgrade “newbie” said he used it successfully for his first ever manual upgrade.

photo credit: AndyWilson


Related Posts:
  • WordPress 2.9.2 Released: Security Release for Trash
  • (Anti) Social-Lists 5/10/09
  • WordPress 2.6.5 – Security and Bug Fix Released
  • (Anti) Social Lists 12/27/09
  • WordPress 2.9 Released on 12/18/09: Highlights
  • Posted In : WordPress Tips
    If you enjoyed this post, please subscribe to my RSS Feed

    Post to Twitter   Post to Delicious   Post to StumbleUpon

    11 Responses to “WordPress 2.8.2 Released – Say What? A Security Release”

    Leave a Comment
    You may use: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> .


    Recent Comments

      • Kim Woodbridge: Hi Dean - Thanks! I'm just glad I got the punctuation right - I've been having a rough week with typos ......
      • Kim Woodbridge: Hi Jim - What's not to love about Mr T?...
      • Kim Woodbridge: Hi - Thanks for visiting! It is funny :-)...
      • Dean Dwyer: Ah the power of the comma. It's April, Fools. Who knew punctuation could be so funny. Thanks for the smile....
      • Kim Woodbridge: Hi Christine - Awesome! Ooh ... something shiny ;-)...
      • Kim Woodbridge: Hi - I wish Twitter lists had started sooner. I've worked on them some but I'm having a hard time finding the time to w...
      • Christine: This has been driving me crazy for... maybe forever! I created too many lists and deleting them was not exactly clear -...
      • Ching Ya: Honestly I can't think of a way to live without lists. :-) Twitter lists, Facebook lists.. all of these have helped me a...