Wordpress 2.3.3
Urgent security update! Update immediately, especially if new users can register on your blog.
WordPress 2.3.3 is an urgent security release. A flaw was found in our XML-RPC implementation such that a specially crafted request would allow any valid user to edit posts of any other user on that blog. In addition to fixing this security flaw, 2.3.3 fixes a few minor bugs. If you are interested only in the security fix, download the fixed version of xmlrpc.php and copy it over your existing xmlrpc.php. Otherwise, you can get the entire release here.
BRB, I have to upgrade five Wordpress installations. ![]()
Tags: security, update, wordpress
February 5th, 2008 at 12:55 pm
[…] Puneţi mâna şi updataţi Wordpress-ul la versiunea 2.3.3 sau măcar dezactivaţi inregistrarea userilor noi, ca s-a găsit înca un bug nasol. Mai multe aici. […]
February 5th, 2008 at 1:45 pm
I have to upgrade 13:)) hope that will not bring me bad luck:p
February 5th, 2008 at 1:49 pm
13 blogs?
Why don’t you use Wordpress MU?
February 5th, 2008 at 1:57 pm
1. security bugs
2. i can’t use it with my current dns server. it doesn’t offer me the option to redirect all subdomains of a certain domain to an ip address:|
February 5th, 2008 at 9:32 pm
I haven’t watched it too closely, but I haven’t seen security bugs specific for WP MU.
And you can add DNS records for every subdomain you want to use.
Anyway, I’m going to give it a try. Five wp installations are IMHO already too many to maintain (yeah, I’m lazy). I don’t want to imagine how much time it takes to maintain all 13 of yours.
February 5th, 2008 at 10:17 pm
the whole upgrade took <2mins. Total Commander (yes,winblowz) rullz!
And about maintenance, 4 of the owners write <3 posts per month. More are the spam comments:D