Posted on 24 October, 2008 By Kim Woodbridge 10 Comments

WordPress: Security Update 2.6.3 Released

 
Share

Bank Security Guard (by Brad & Sabrina)

Earlier this week, I asked if you were an early adopter with WordPress upgrades. Following on the heels of that inquiry is a WordPress security update, which brings WordPress up to version 2.6.3. If you are running 2.6 or higher, you can see the message about the upgrade on your dashboard.

A vulnerability has been found with the snoopy.php file, which is responsible for the RSS feeds on your dashboard. This is not a crucial issue but snoopy.php is used by a number of plugins so, as always, I recommend upgrading.

There is, however, good news for people who are already running 2.6.2. According to Joost de Valk, at yoast.com, only three files need to be updated if you are already running the most recent version. Replacing three files via ftp or your cpanel file manager is SO much easier than a full upgrade. The three files are:

  1. wp-includes/class-snoopy.php
  2. wp-includes/version.php
  3. wp-admin/includes/media.php

Joost also warns to make sure that you replace wp-admin/includes/media.php and not /includes/media.php

Of course, if you are running a version earlier than 2.6.2 you will need to do the full upgrade. As always, backup everything first.

I replaced the three files on this site this morning and everything is working fine. I have two more installations to upgrade as well as my testing server, which I will do later today.

Over at The Blog Herald, Chris Garrett asks if WordPress has too many upgrades too often. I know we’ve touched upon this issue in the early adopter article but what do you think? Are there too many upgrades? Are you glad that security issues are addressed immediately? Do you think upgrades / updates should be simplified? Feel free to answer here or over at The Blog Herald – quite a discussion has started there already.

photo credit: Brad & Sabrina


Related Posts:
  • WordPress 2.8.1 Released
  • WordPress Optimization Tips – Slideshow
  • WordPress 2.6.5 – Security and Bug Fix Released
  • WordPress 2.9.2 Released: Security Release for Trash
  • (Anti) Social Lists 12/27/09
  • Posted In : WordPress Tips
    If you enjoyed this post, please subscribe to my RSS Feed. You can also connect with my Facebook page or follow me on Twitter.



    10 Responses to “WordPress: Security Update 2.6.3 Released”

    Leave a Comment
    You may use: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> .

    CommentLuv Enabled

    Recent Comments

      • Ari Herzog: Agreed on the updates/inbox snafu. I rarely see page updates and I know where they are! .-= Ari Herzog´s last blog .....
      • jayson: Kim, Love the themes. I am looking to update the theme on my site to something more appropriate. My site is all abou...
      • vered: "I wish more people would use this. I think it’s silly when I get updates for things occuring in Kansas and California –...
      • Dennis Edell @ Direct Sales Marketing: I was speaking generally, not specifically this month. how exactly do you work things? .-= Dennis Edell @ Direct Sales M...
      • Lucy Beer: Unfortunately I think next to no-one actually sees those "Updates". They're buried in a subsection of the inbox and I do...
      • Kim Woodbridge: Hi Marbella - Thanks! I had a great time....
      • Kim Woodbridge: Hi Julie - I'll probably try kayaking again next summer but I don't know if I will become much of a kayaker - I had a di...
      • Kim Woodbridge: Hi Vered - If you ever get the chance, you should go. It's like a different world - it's so quiet and peaceful....

    About

    Kim Woodbridge is an accomplished Information and Technical Consultant specializing in the entire implementation of a WordPress based website including installation, theme design, upgrades, unique customizations and ongoing site maintenance.

    Wordpress Services

    • Installation, upgrades and maintenance
    • Conversion of existing html and css templates
    • Theme and plugin recommendations
    • CSS customizations
    • Troubleshooting and tweaks for unique situations
    • Customization for individual blogging goals and needs
    • Training and advice