Wordpress (Version 2.3.3) is out upgrade now
The latest version of Wordpress - 2.3.3 is out now. It includes a major fix to the XML RPC file xmlrpc.php
A flaw was found in our XML-RPC implementation such that a specially crafted request would allow any valid user to edit posts of any other user on that blog. In addition to fixing this security flaw, 2.3.3 fixes a few minor bugs. If you are interested only in the security fix, download the fixed version of xmlrpc.php and copy it over your existing xmlrpc.php. Otherwise, you can get the entire release here.
Also, there is a vulnerability in the WP-Forum plugin that is being actively exploited right now. If you are using this plugin, please remove it until an update is available.
For more information about upgrading your Wordpress installation visit Wordpress Upgrade directions page at Wordpress Codex
Buy me a cup of hot coffee - help me keep posting all through the nightso that you will get the updates automatically to your feed reader.
Tags: Free
You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.





Leave a Reply