<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; wordpress update</title> <atom:link href="http://www.ghacks.net/tag/wordpress-update/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 08:24:54 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>WordPress 3.3.1 Security Update Available</title><link>http://www.ghacks.net/2012/01/04/wordpress-3-3-1-security-update-available/</link> <comments>http://www.ghacks.net/2012/01/04/wordpress-3-3-1-security-update-available/#comments</comments> <pubDate>Tue, 03 Jan 2012 23:03:38 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Web Development]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=55306</guid> <description><![CDATA[A new version of the popular blogging software WordPress has just been released. WordPress admins should already see update notifications in the dashboards of the blogs that they administrate. The update is also already advertised on the official WordPress website. It is as usually possible to update the blog right away from within the admin [...]]]></description> <content:encoded><![CDATA[<p>A new version of the popular blogging software WordPress has just been released. WordPress admins should already see update notifications in the dashboards of the blogs that they administrate. The update is also already advertised on the official WordPress website.</p><p>It is as usually possible to update the blog right away from within the admin dashboard if it has been configured for that, or via file transfer clients if the former option is not available.</p><p>The blog post <a
href="http://wordpress.org/news/2012/01/wordpress-3-3-1/">that</a> announces the new version of WordPress mentions 15 maintenance related fixes and one security related fix that have been applied to the new version. It fails to go into detail but links <a
href="http://core.trac.wordpress.org/query?status=closed&#038;resolution=fixed&#038;milestone=3.3.1&#038;group=resolution&#038;order=priority">to the</a> bug tracker listing which details every fix except for the security issue.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2012/01/wordpress-3-3-1-update.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2012/01/wordpress-3-3-1-update.jpg" alt="wordpress 3.3.1 update" title="wordpress 3.3.1 update" width="290" height="36" class="alignnone size-full wp-image-55307" /></a></p><p>At least one of the issues that have been fixed in WordPress 3.3.1 seem to have affected this site. I was recently noticing issues with the author biographies not being displayed anymore on article pages, and it took a whole day to find a working workaround. It appears now that this was a bug that got fixed with this new WordPress release.</p><p>The security vulnerability is only briefly mentioned in the blog post where it is described as a cross-site scripting vulnerability that is affecting WordPress version 3.3.</p><p>The WordPress Codex <a
href="http://codex.wordpress.org/Version_3.3.1">lists all</a> files that have been revised in the new version. It is theoretically possible to only upload those files to the site to save time and bandwidth.</p><p>I have already updated several WordPress sites to version 3.3.1 and did not notice any odd behavior or issues with the updating or site operation.</p><p>WordPress admins are encouraged to update their blogs as soon as possible to protect it from the security vulnerability and to resolve the stability issues that have been fixed with the update.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2012/01/04/wordpress-3-3-1-security-update-available/feed/</wfw:commentRss> <slash:comments>9</slash:comments> </item> <item><title>WordPress 3.3 Now Available</title><link>http://www.ghacks.net/2011/12/13/wordpress-3-3-now-available/</link> <comments>http://www.ghacks.net/2011/12/13/wordpress-3-3-now-available/#comments</comments> <pubDate>Tue, 13 Dec 2011 10:25:20 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Web Development]]></category> <category><![CDATA[blog]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=54315</guid> <description><![CDATA[The developers of the popular blogging platform WordPress have released version 3.3 just a few minutes ago. WordPress 3.3 update notifications should appear right in the admin interface of the blog. Users can use the internal updater to update from within the admin interface, or by downloading the new version from the official site to [...]]]></description> <content:encoded><![CDATA[<p>The developers of the popular blogging platform WordPress have released version 3.3 just a few minutes ago. WordPress 3.3 update notifications should appear right in the admin interface of the blog. Users can use the internal updater to update from within the admin interface, or by downloading the new version from the official site to update manually.</p><p>The <a
href="http://codex.wordpress.org/Version_3.3">What&#8217;s New</a> page at the WordPress Codex highlights the &#8211; many &#8211; changes of the new version. WordPress admins will instantly notice several changes to the applications admin interface. A new toolbar is displayed on top of the dashboard that combines the features of the admin bar and the admin header.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/12/wordpress-admin-bar.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/12/wordpress-admin-bar-600x102.jpg" alt="wordpress admin bar" title="wordpress admin bar" width="600" height="102" class="alignnone size-medium wp-image-54316" /></a></p><p>The new bar links directly to plugin and theme updates, comments awaiting moderation and the New menu with options to create new content on the blog.  (There is a function to remove some of the elements that are shown in the admin bar. Credits to <a
href="https://gist.github.com/1471510">Sergej Müller</a>)</p><p>Another change are &#8220;fly-out&#8221; menus in the admin interface. All submenus of a menu are displayed when you hoover the mouse over the menu. This saves a click and improves the admin&#8217;s workflow.</p><p>WordPress editors will notice a new file uploader. The developers have done away with the four upload buttons for specific type of media, and replaced it with a single button. The new uploader supports drag and drop operations and file browsing to select files to upload. Support for rar and 7z files have been added to the file uploader.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/12/wordpress-drag-drop-upload.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/12/wordpress-drag-drop-upload.jpg" alt="wordpress drag drop upload" title="wordpress drag drop upload" width="455" height="284" class="alignnone size-full wp-image-54317" /></a></p><p>WordPress admins who switch between themes regularly will notice that widgets are not lost anymore when they do that.</p><p>A video has been created that highlights several of the new features.</p><p><embed
type="application/x-shockwave-flash" src="http://s0.videopress.com/player.swf?v=1.03" width="400" height="224" wmode="direct" seamlesstabbing="true" allowfullscreen="true" allowscriptaccess="always" overstretch="true" flashvars="guid=I7NAw9Zk&amp;isDynamicSeeking=true"></embed></p><p>The WordPress backend has been updated as well with hundreds of bug fixes and performance improvements. It is to early to tell if the improvements will have a significant impact on the blog&#8217;s server resource usage or loading times.</p><p>Have you updated your blog to WordPress 3.3 yet? If so, what do you think of the new version?</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/12/13/wordpress-3-3-now-available/feed/</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>WordPress 3.2.1 Released, Maintenance Update</title><link>http://www.ghacks.net/2011/07/13/wordpress-3-2-1-released-maintenance-update/</link> <comments>http://www.ghacks.net/2011/07/13/wordpress-3-2-1-released-maintenance-update/#comments</comments> <pubDate>Wed, 13 Jul 2011 06:25:13 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Web Development]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress 3.2.1]]></category> <category><![CDATA[wordpress security]]></category> <category><![CDATA[wordpress update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=47746</guid> <description><![CDATA[About a week after the push to version 3.2 comes the next WordPress update. Updates that follow quickly after a major release are usually either security or bug related. According to WordPress, version 3.2.1 is a maintenance release that fixes a server incompatibility related to JSON, and a few other issues that came up after [...]]]></description> <content:encoded><![CDATA[<p>About a week after the push to version 3.2 comes the next WordPress update. Updates that follow quickly after a major release are usually either security or bug related. According to WordPress, version 3.2.1 is a maintenance release that fixes a server incompatibility related to JSON, and a few other issues that came up after the release of WordPress 3.2.</p><p>Please note that this is not a security release, which means you have got more time than usual to update your WordPress site to the new version of the blogging script.</p><p>WordPress Trac <a
href="http://core.trac.wordpress.org/log/branches/3.2/?rev=18436&#038;stop_rev=18398">lists</a> all the changes in the new release. If you look at the list you will notice that most are design related. Many fix or improve the Twenty Eleven default theme that ships with WordPress, while others do the same for the new admin interface introduced in WordPress 3.2.</p><p>Still no option to change the default font for the admin interface easily, unfortunately.</p><p>Updates are makinguse of the new &#8220;fast&#8221; update mechanism which only updates files that have been changed, instead of all files of a WordPress installation. Users who update via their WordPress Dashboard should notice that the procedure is speedier than before.</p><p>Updates are available via Dashboard > Updates. WordPress administrators can download the new version of WordPress from there or update directly if their blog has been configured properly for that.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/07/wordpress-3-2-1.png" alt="wordpress 3.2.1" title="wordpress 3.2.1" width="391" height="258" class="alignnone size-full wp-image-47748" /></p><p>The new version is alternatively available <a
href="http://wordpress.org/download/">at the</a> official WordPress website.</p><p>I have updated six blogs so far and did not notice any problems with the new updating mechanism or the new version of WordPress itself.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/07/13/wordpress-3-2-1-released-maintenance-update/feed/</wfw:commentRss> <slash:comments>10</slash:comments> </item> <item><title>WordPress 3.2 Released, Design Refresh</title><link>http://www.ghacks.net/2011/07/05/wordpress-3-2-released-design-refresh/</link> <comments>http://www.ghacks.net/2011/07/05/wordpress-3-2-released-design-refresh/#comments</comments> <pubDate>Tue, 05 Jul 2011 06:32:29 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Web Development]]></category> <category><![CDATA[blogging]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress 3.2]]></category> <category><![CDATA[wordpress release]]></category> <category><![CDATA[wordpress update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=47404</guid> <description><![CDATA[Two WordPress releases in short time, that puts some pressure on system administrators and website owners. That is, if you update your blogs as soon as the updates come out, and not weeks afterwards. WordPress 3.2 is not a security update, which means that webmasters have more time to update their blogs to the new [...]]]></description> <content:encoded><![CDATA[<p>Two WordPress releases in short time, that puts some pressure on system administrators and website owners. That is, if you update your blogs as soon as the updates come out, and not weeks afterwards. WordPress 3.2 is not a security update, which means that webmasters have more time to update their blogs to the new version, as it is not something that they must do right away to protect it from hackers and exploits.</p><p>That&#8217;s good because the new version introduces new system requirements that webmasters should make sure their server supports, before they upgrade. WordPress 3.2 requires as a minimum MySql 5.0.15 and PHP 5.2.4. That&#8217;s a big step from MySQL 4.1.2 and PHP 4.3. Contact your hoster if you are not sure if you server supports the minimum requirements.</p><p>Experienced webmasters can also create a php file with &lt;? PHPINFO(); ?&gt; as the content and upload it to their server. The file displays the information, among many others, in the browser when opened there.</p><p>The highlights of WordPress 3.2 in 40 words or less: WordPress comes with a refreshed admin design, a full screen editor for distraction free blogging, a new default HTML5 theme and an extended admin bar.</p><p>There are other things, largely under the hood that will make webmasters happy. This includes faster page loading times, dropped support for Internet Explorer 6, additional performance and speed improvements and caching of admin dashboard widgets to reduce the site&#8217;s memory footprint.</p><p><object
width="400" height="224" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param
name="src" value="http://s0.videopress.com/player.swf?v=1.02" /><param
name="wmode" value="direct" /><param
name="seamlesstabbing" value="true" /><param
name="allowfullscreen" value="true" /><param
name="allowscriptaccess" value="always" /><param
name="overstretch" value="true" /><param
name="flashvars" value="guid=ac07H291" /><embed
width="400" height="224" type="application/x-shockwave-flash" src="http://s0.videopress.com/player.swf?v=1.02" wmode="direct" seamlesstabbing="true" allowfullscreen="true" allowscriptaccess="always" overstretch="true" flashvars="guid=ac07H291" /></object></p><p>The new admin interface seems to use new typography as well, at least in some parts. Especially the font in HTML editing mode feels strange with its white space between words and a new line height. Editors who switch to the visual mode on the other hand seem to get a default font (does anyone know if it is possible to change the font in WordPress admin?)</p><p>The update notifications are as usual available right on the admin backend of the blog. Webmasters can update their blogs from within their, if configured this way. This is the fastest update option. An alternative is the download of the new version <a
href="http://wordpress.org/news/2011/07/gershwin/">from the</a> official website and updating via ftp or sftp.</p><p>I have updated five blogs yesterday evening and the update went well without difficulties. I will now continue to upgrade my other twenty or so blogs, such fun..</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/07/05/wordpress-3-2-released-design-refresh/feed/</wfw:commentRss> <slash:comments>10</slash:comments> </item> <item><title>WordPress 3.1.4 Security Update Released</title><link>http://www.ghacks.net/2011/06/30/wordpress-3-1-4-security-update-released/</link> <comments>http://www.ghacks.net/2011/06/30/wordpress-3-1-4-security-update-released/#comments</comments> <pubDate>Wed, 29 Jun 2011 22:18:48 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Web Development]]></category> <category><![CDATA[blogging platform]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress security]]></category> <category><![CDATA[wordpress update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=47152</guid> <description><![CDATA[It seems that the WordPress developers have a thing for releasing a new version of WordPress shortly before I&#8217;m going to bed. Whenever they do it means that I have to stay away to find out if it fixes security vulnerabilities. If it does, I update all of my blogs immediately. Instead of going to [...]]]></description> <content:encoded><![CDATA[<p>It seems that the WordPress developers have a thing for releasing a new version of WordPress shortly before I&#8217;m going to bed. Whenever they do it means that I have to stay away to find out if it fixes security vulnerabilities. If it does, I update all of my blogs immediately. Instead of going to bed, I&#8217;m spending between one and two hours updating the sites. Not that pleasant.</p><p>WordPress 3.1.4. has just been released and the developers refer to it as a security and maintenance upgrade. The new version fixes one known vulnerability that &#8220;could allow a malicious Editor-level user to gain further access to the site&#8221;. If you are running a single author blog you are safe from this.</p><p>I&#8217;d still recommend to update the blog as soon as possible because of security hardening additions to the blogging platform.</p><p>The update is as usually available as a direct download, install and update from within the WordPress admin interface, and as a separate download from the official WordPress website. I have updated a total of five blogs so far &#8211; including Ghacks Technology News &#8211; and encountered no problems or issues after the update. While it may be to early to tell, it is relatively safe to say that the update won&#8217;t break the blog.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/06/wordpress-update-3-1-4.png" alt="wordpress update 3.1.4" title="wordpress update 3.1.4" width="387" height="233" class="alignnone size-full wp-image-47153" /></p><p>WordPress admins who are interested in all changes in the WordPress 3.1.4 release find them listed on <a
href="http://core.trac.wordpress.org/log/branches/3.1/?action=stop_on_copy&#038;mode=stop_on_copy&#038;rev=18375&#038;stop_rev=18047&#038;limit=100">WordPress trac</a>.</p><p>The developers have furthermore released the third and final release candidate of WordPress 3.2 which will be released in the near future. While I would not suggest to update a public blog to that version yet, it is clear that it won&#8217;t be long until the final version is released. Likely again before my bedtime.</p><p>You find additional information about the features and changes in WordPress 3.2 on the <a
href="http://wordpress.org/news/2011/05/wordpress-3-2-beta-1/">official beta</a> announcement post over at the WordPress website.</p><p>Have you updated your blogs yet? If so, have you encountered any issues with this update?</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/06/30/wordpress-3-1-4-security-update-released/feed/</wfw:commentRss> <slash:comments>10</slash:comments> </item> <item><title>WordPress 3.1.3 Security Update Released</title><link>http://www.ghacks.net/2011/05/25/wordpress-3-1-3-security-update-released/</link> <comments>http://www.ghacks.net/2011/05/25/wordpress-3-1-3-security-update-released/#comments</comments> <pubDate>Wed, 25 May 2011 20:32:16 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress security]]></category> <category><![CDATA[wordpress update]]></category> <category><![CDATA[wordpress vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=45561</guid> <description><![CDATA[An update for the popular blogging software WordPress was just released. The developers classify the update as a security update, it appears however that it fixes no zero day vulnerability. The WordPress blog lists the following security enhancements and fixes in WordPress 3.1.3. Various security hardening Taxonomy query hardening Prevent sniffing out user names of [...]]]></description> <content:encoded><![CDATA[<p>An update for the popular blogging software WordPress was just released. The developers classify the update as a security update, it appears however that it fixes no zero day vulnerability.</p><p>The WordPress blog <a
href="http://wordpress.org/news/">lists</a> the following security enhancements and fixes in WordPress 3.1.3.</p><ul><li>Various security hardening</li><li>Taxonomy query hardening</li><li>Prevent sniffing out user names of non-authors by using canonical redirects.</li><li>Media security fixes</li><li>Improves file upload security on hosts with dangerous security settings.</li><li>Cleans up old WordPress import files if the import does not finish.</li><li> Introduce “clickjacking” protection in modern browsers on admin and login pages.</li></ul><p>Interested users can consult <a
href="http://core.trac.wordpress.org/log/branches/3.1/?action=stop_on_copy&#038;mode=stop_on_copy&#038;rev=18023&#038;stop_rev=17805&#038;limit=100">WordPress trac</a> for detailed information on all fixes that have been applied to this release.</p><p>The developers have added quite some security hardening to the new release as you can see from the list of changes above. It is still recommended to update WordPress installations as soon as possible to improve security and close the security and privacy vulnerabilities fixed in the release.</p><p>Self-hosted WordPress blogs are already picking up on the update and notifying administrators in the dashboard about the update.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/05/wordpress-update.png" alt="wordpress update" title="wordpress update" width="414" height="261" class="alignnone size-full wp-image-45562" /></p><p>It is as usual possible to apply and install the WordPress update right from the admin dashboard, or by downloading the new release from WordPress to install it manually by uploading file to the server.</p><p>The WordPress Codex <a
href="http://codex.wordpress.org/Version_3.1.3">lists</a> the file changes in this new release.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/05/25/wordpress-3-1-3-security-update-released/feed/</wfw:commentRss> <slash:comments>6</slash:comments> </item> <item><title>WordPress 3.1.2 Released, Security Update</title><link>http://www.ghacks.net/2011/04/26/wordpress-3-1-2-released-security-update/</link> <comments>http://www.ghacks.net/2011/04/26/wordpress-3-1-2-released-security-update/#comments</comments> <pubDate>Tue, 26 Apr 2011 20:48:35 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Web Development]]></category> <category><![CDATA[blog]]></category> <category><![CDATA[security update]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=44411</guid> <description><![CDATA[WordPress has just released a new version of the popular blogging platform. WordPress 3.1.2 is a security update which makes it a mandatory update for all self-hosted WordPress sites. The update &#8220;addresses a vulnerability that allowed Contributor-level users to improperly publish posts&#8221; notes Ryan Boren at the official WordPress blog. The WordPress developers suggest to [...]]]></description> <content:encoded><![CDATA[<p>WordPress has just released a new version of the popular blogging platform. WordPress 3.1.2 is a security update which makes it a mandatory update for all self-hosted WordPress sites. The update &#8220;addresses a vulnerability that allowed Contributor-level users to improperly publish posts&#8221; <a
href="http://wordpress.org/news/2011/04/wordpress-3-1-2/">notes</a> Ryan Boren at the official WordPress blog.</p><p>The WordPress developers suggest to update immediately, especially if users can register as contributors on the blog. WordPress 3.1.2 fixes several non-security related issues which you can see a list of at the <a
href="http://core.trac.wordpress.org/query?milestone=3.1.2">issue tracker</a> over at the WordPress website.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/04/wordpress-update1-570x203.png" alt="wordpress update" title="wordpress update" width="570" height="203" class="alignnone size-medium wp-image-44412" /></p><p>Nothing to spectacular fixed though, take a look below for the list.</p><ul><li>It&#8217;s tricky to drag metaboxes</li><li>Apostrophe in first/last/nickname causes JS error on user profile page</li><li>Missing closing &lt;/fieldset&gt; in user-edit.php for &#8220;show admin bar&#8221;</li><li>Multiple tag queries broken</li><li>WP_User_Query ordered by post_count doesn&#8217;t work if prefix is not wp_</li><li>WordPress 3.1.1 breaks date archive filtering by tag or category</li><li>Walker_PageDropdown doesn&#8217;t filter titles correctly</li><li>Too much escaping for pages when using Quick Edit</li></ul><p>WordPress administrators can update their blogs either directly from the WordPress Dashboard with a click on the Update Automatically button, or by downloading the new release <a
href="http://wordpress.org/download/">from the</a> official WordPress website, uploading the files manually to the server and running the upgrade script afterwards.</p><p>I have just updated more than a dozen WordPress blog to version 3.1.2 and the automatic update worked without difficulties in every instance. WordPress admins should not encounter any page display problems on the frontend or backend after applying the update.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/04/26/wordpress-3-1-2-released-security-update/feed/</wfw:commentRss> <slash:comments>8</slash:comments> </item> <item><title>WordPress 3.1.1 Released, Fixes Security Issues</title><link>http://www.ghacks.net/2011/04/05/wordpress-3-1-1-released-fixes-security-issues/</link> <comments>http://www.ghacks.net/2011/04/05/wordpress-3-1-1-released-fixes-security-issues/#comments</comments> <pubDate>Tue, 05 Apr 2011 20:56:51 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[The Web]]></category> <category><![CDATA[blogging]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=43501</guid> <description><![CDATA[The developers of the popular WordPress blogging script have just released an update that raises the version of WordPress to 3.1.1. WordPress 3.1.1 is a security update which means that it is a mandatory update for all webmasters who run public self-hosted WordPress blogs. The blog post that announced the new version of WordPress mentioned [...]]]></description> <content:encoded><![CDATA[<p>The developers of the popular WordPress blogging script have just released an update that raises the version of WordPress to 3.1.1. WordPress 3.1.1 is a security update which means that it is a mandatory update for all webmasters who run public self-hosted WordPress blogs. The blog post that <a
href="http://wordpress.org/news/">announced</a> the new version of WordPress mentioned three security issues that have been fixed in the release: &#8220;The first hardens CSRF prevention in the media uploader. The second avoids a PHP crash in certain environments when handling devilishly devised links in comments, and the third addresses an XSS flaw&#8221;.</p><p>That alone should be reason enough to update WordPress to the latest version. The post mentions performance improvements without going into further details. It is therefor not clear if the improvements are measurable, and which areas of the platform have been improvement. The remaining changes list fixes for IIS6 support, taxonomy and pathinfo permalinks and various &#8220;query and taxonomy edge cases that caused some plugin compatibility issues&#8221;.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/04/wordpress-update.png"><img
src="http://www.ghacks.net/wp-content/uploads/2011/04/wordpress-update.png" alt="wordpress update" title="wordpress update" width="427" height="143" class="alignnone size-full wp-image-43502" /></a></p><p>Update notifications are not displayed on all WordPress blogs yet. Webmasters should click on Dashboard > Updates to force WordPress to check for new updates. The WordPress 3.1.1. release should be listed on that page then. It is then possible to update the WordPress blog automatically from within the admin interface, or to download the new release and update the blog manually by uploading all files to the server and running the wp-admin/update.php script afterwards.</p><p>I have just finished updating 20 different WordPress blogs and the automatic updating worked on all but one without errors or problems. The one blog is a special case and it is likely that a plugin or special script interfered with the update.</p><p>The latest version of WordPress can be downloaded <a
href="http://wordpress.org/download/">from this</a> page.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/04/05/wordpress-3-1-1-released-fixes-security-issues/feed/</wfw:commentRss> <slash:comments>6</slash:comments> </item> <item><title>WordPress 3.1 Released</title><link>http://www.ghacks.net/2011/02/23/wordpress-3-1-released/</link> <comments>http://www.ghacks.net/2011/02/23/wordpress-3-1-released/#comments</comments> <pubDate>Wed, 23 Feb 2011 18:11:13 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[The Web]]></category> <category><![CDATA[blog]]></category> <category><![CDATA[blogging]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=40150</guid> <description><![CDATA[A new version of the popular blogging platform WordPress has just been released by its developers. WordPress 3.1 contains bug fixes, the developers speak of more than 729 closed issues, new features and several interface changes or enhancements. The update is not a security update which means that there is no rush to install it [...]]]></description> <content:encoded><![CDATA[<p>A new version of the popular blogging platform WordPress has just been released by its developers. WordPress 3.1 contains bug fixes, the developers speak of more than 729 closed issues, new features and several interface changes or enhancements.</p><p>The update is not a security update which means that there is no rush to install it directly.</p><p>Among the new features is the option to link to existing content easier. This is done via the standard link button in the WordPress writing panel and the selection of &#8220;Or link to existing content&#8221;.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/02/wordpress-internal-links.jpg"><img
class="alignnone size-full wp-image-40152" title="wordpress internal links" src="http://www.ghacks.net/wp-content/uploads/2011/02/wordpress-internal-links.jpg" alt="wordpress internal links" width="477" height="467" /></a></p><p>It is possible to search for related content or select one of the most recent items. The writing interface has been overhauled. The developers have many interface elements that were shown by default of the screen which should be beneficial to new users. All writing elements can be added again via the Screen Options at the top of the page.</p><p>Another addition is the new admin bar that is displayed to WordPress administrators when they navigate the WordPress frontend. The bar is actually not displayed on all of my blogs right now. I&#8217;m not sure why that is the case (likely because of CSS minifying or merging) but there is thankfully a way to disable the admin bar.</p><p>Open Users &gt; Your Profile and locate Show Admin Bar near the top.  Remove the checkmark from &#8220;when viewing site&#8221; to disable it.</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/02/wordpress-disable-admin-bar.jpg"><img
class="alignnone size-full wp-image-40154" title="wordpress disable admin bar" src="http://www.ghacks.net/wp-content/uploads/2011/02/wordpress-disable-admin-bar.jpg" alt="wordpress disable admin bar" width="486" height="347" /></a></p><p>Other noteworthy features are:</p><ul><li>post formats, meta information used by themes</li><li>network admin, moves the Super Admin menu out of the regular admin interface</li><li>list-type admin screens, now sortable by column, better pagination</li><li>exporter / importer, was overhauled.</li><li>advanced queries, again something for developers</li><li>custom content type improvements, again developer related</li><li>refreshed blue admin color scheme</li></ul><p>Interested users can <a
href="http://codex.wordpress.org/Version_3.1">visit the</a> WordPress Codec for an in depth overview of all the features that have been added, improved or changed in the recent release.</p><p>WordPress administrators can upgrade their blog to WordPress 3.1 either directly from within the admin interface or by downloading WordPress 3.1 <a
href="http://wordpress.org/download/">from the</a> official website and installing the new version manually.</p><p>&nbsp;</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/02/23/wordpress-3-1-released/feed/</wfw:commentRss> <slash:comments>11</slash:comments> </item> <item><title>WordPress 3.0.5 Released</title><link>http://www.ghacks.net/2011/02/08/wordpress-3-0-5-released/</link> <comments>http://www.ghacks.net/2011/02/08/wordpress-3-0-5-released/#comments</comments> <pubDate>Tue, 08 Feb 2011 07:46:37 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Software]]></category> <category><![CDATA[The Web]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress security]]></category> <category><![CDATA[wordpress update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=39698</guid> <description><![CDATA[An update to the popular WordPress blogging platform has just been released. The announcement should appear in the admin interface of the WordPress blog. If it does not check the Updates entry on the left sidebar of the admin menu. According to the developers, WordPress 3.0.5 is a &#8221; security hardening update for all previous [...]]]></description> <content:encoded><![CDATA[<p>An update to the popular WordPress blogging platform has just been released. The announcement should appear in the admin interface of the WordPress blog. If it does not check the Updates entry on the left sidebar of the admin menu.</p><p>According to the developers, WordPress 3.0.5 is a &#8221; security hardening update for all previous WordPress versions&#8221; that fixes two moderate security issues and one information disclosure issue, and adds two security enhancements to the blogging application.</p><p>The security issues could have allowed &#8220;a Contributor- or Author-level user to gain further access to the site&#8221;, the information disclosure issue &#8220;could have allowed an Author-level user to view contents of posts they should not be able to see&#8221;.</p><p>The two security enhancements &#8220;improved the security of any plugins which were not properly leveraging our security API&#8221; and &#8220;offer additional defense in depth against a vulnerability that was fixed in previous release&#8221;. (<a
href="http://wordpress.org/news/">via</a>)</p><p><a
href="http://www.ghacks.net/wp-content/uploads/2011/02/wordpress-3-0-5.jpg"><img
src="http://www.ghacks.net/wp-content/uploads/2011/02/wordpress-3-0-5.jpg" alt="wordpress 3 0 5" title="wordpress 3 0 5" width="441" height="188" class="alignnone size-full wp-image-39699" /></a></p><p>The <a
href="http://codex.wordpress.org/Version_3.0.5">summary</a> lists the following changes:</p><ul><li> Fix XSS bug: Properly encode title used in Quick/Bulk Edit, and offer additional sanitization to various fields. Affects users of the Author or Contributor role.</li><li> Fix XSS bug: Preserve tag escaping in the tags meta box. Affects users of the Author or Contributor role.</li><li> Fix potential information disclosure of posts through the media uploader. Affects users of the Author role.</li><li> Enhancement: Force HTML filtering on comment text in the admin</li><li> Enhancement: Harden check_admin_referer() when called without arguments, which plugins should avoid.</li><li> Update the license to GPLv2 (or later) and update copyright information for the KSES library</li></ul><p>WordPress 3.0.5 is <a
href="http://wordpress.org/download/">available</a> for download at the official WordPress site as well for users who want to install the update manually on their server.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/02/08/wordpress-3-0-5-released/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>WordPress 3.0.4 Released, Fixes Critical Security Vulnerability</title><link>http://www.ghacks.net/2010/12/30/wordpress-3-0-4-released-fixes-critical-security-vulnerability/</link> <comments>http://www.ghacks.net/2010/12/30/wordpress-3-0-4-released-fixes-critical-security-vulnerability/#comments</comments> <pubDate>Wed, 29 Dec 2010 23:20:53 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress blog]]></category> <category><![CDATA[wordpress security]]></category> <category><![CDATA[wordpress update]]></category> <category><![CDATA[wordpress vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=38506</guid> <description><![CDATA[An update to the popular blogging platform WordPress has just been released that fixes a critical security vulnerability in the software. WordPress 3.0.4 is already available for download at the official website and through the updating options on installed WordPress blogs. The update is currently not announced on the frontpage of the admin interface which [...]]]></description> <content:encoded><![CDATA[<p>An update to the popular blogging platform WordPress has just been released that fixes a critical security vulnerability in the software. WordPress 3.0.4 is already available for download at the official website and through the updating options on installed WordPress blogs.</p><p>The update is currently not announced on the frontpage of the admin interface which means that WordPress admins need to click on Updates to see the update options.</p><p>It is as usually possible to install the update right away by downloading it directly to the server running the blog. The script handles the download, unpacking and installation of the new version automatically.</p><p>Users who want to test the release first can also download it instead to do just that.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2010/12/wordpress-3-0-4-update.jpg" alt="wordpress 3.0.4 update" title="wordpress 3.0.4 update" width="442" height="252" class="alignnone size-full wp-image-38507" /></p><p>The vulnerability reads:</p><blockquote><p>Fix XSS vulnerabilities in the KSES library: Don&#8217;t be case sensitive to attribute names. Handle padded entities when checking for bad protocols. Normalize entities before checking for bad protocols in esc_url()</p></blockquote><p>WordPress rates the vulnerability as critical which means that webmasters should update their blogs as soon as possible to protect it from possible exploits of the issue.</p><p><a
href="http://wordpress.org/">WordPress</a> is also available directly at the official website.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/12/30/wordpress-3-0-4-released-fixes-critical-security-vulnerability/feed/</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>WordPress 3.03 Security Update Released</title><link>http://www.ghacks.net/2010/12/09/wordpress-3-03-security-update-released/</link> <comments>http://www.ghacks.net/2010/12/09/wordpress-3-03-security-update-released/#comments</comments> <pubDate>Wed, 08 Dec 2010 23:24:20 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[The Web]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress security]]></category> <category><![CDATA[wordpress update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=37735</guid> <description><![CDATA[Why is it that WordPress updates are always released the minute before I want to go to bed? WordPress has just released a new update that brings the version of their popular blogging platform to 3.03. The update is a security update which makes it a mandatory update for all WordPress webmasters hosting blogs on [...]]]></description> <content:encoded><![CDATA[<p>Why is it that WordPress updates are always released the minute before I want to go to bed? WordPress has just released a new update that brings the version of their popular blogging platform to 3.03. The update is a security update which makes it a mandatory update for all WordPress webmasters hosting blogs on their own servers,</p><p>So what&#8217;s the security vulnerability about? <a
href="http://wordpress.org/news/2010/12/wordpress-3-0-3/">The</a> WordPress blog states that it is about issues &#8220;in the remote publishing interface, which under certain circumstances allowed Author- and Contributor-level users to improperly edit, publish, or delete posts&#8221;.</p><p>That in turn means that single-author blogs are not affected by the vulnerability directly. Webmasters should still consider updating right away to prevent future damage or indirect damage if someone manages to get access to user accounts on the blog or the ability to create them.</p><p>The issue affects sites that have remote publishing enabled. Sites that do not have it enabled are not affected. Then again, it is always a good idea to update to the latest release to close potential security issues right away.</p><p>WordPress admins can check if remote publishing is enabled by going to Settings > Writing in their WordPress admin interface.</p><p>The update is as usually available directly in WordPress. Users can update their blogs from within WordPress which is the fastest and most convenient solution, or by downloading WordPress <a
href="http://wordpress.org/">from the</a> official website and installing the update manually.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/12/09/wordpress-3-03-security-update-released/feed/</wfw:commentRss> <slash:comments>8</slash:comments> </item> <item><title>WordPress 3.02 Security Update Released</title><link>http://www.ghacks.net/2010/12/01/wordpress-3-02-security-update-released/</link> <comments>http://www.ghacks.net/2010/12/01/wordpress-3-02-security-update-released/#comments</comments> <pubDate>Wed, 01 Dec 2010 10:53:36 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[blog]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress security]]></category> <category><![CDATA[wordpress update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=37491</guid> <description><![CDATA[The WordPress developers have just released a security update to the popular blogging platform. WordPress admins should see the update notification in the admin interface. To install the WordPress update they can either download it manually from the WordPress website, upload it to their ftp and perform the necessary steps to update the platform or [...]]]></description> <content:encoded><![CDATA[<p>The WordPress developers have just released a security update to the popular blogging platform. WordPress admins should see the update notification in the admin interface. To install the WordPress update they can either download it manually from the WordPress website, upload it to their ftp and perform the necessary steps to update the platform or perform a direct update from within WordPress.</p><p>It is recommended to backup the blog before performing the update to be able to restore to a previous version in case something goes wrong during the update.</p><p>The official release notes <a
href="http://codex.wordpress.org/Version_3.0.2">mention</a> that a moderate security issues have been fixed where &#8220;a malicious Author-level user could gain further access to the site&#8221;. In addition to that bugs have been fixed and security hardening added to the blog.</p><blockquote><p> Remove pingback/trackback blogroll whitelisting feature as it can easily be abused. (#13887)<br
/> Fix canonical redirection for permalinks containing %category% with nested categories and paging. (#13471)<br
/> Fix occasional irrelevant error messages on plugin activation. (#15062)<br
/> Minor XSS fixes in request_filesystem_credentials() and when deleting a plugin. (r16367, r16373)<br
/> Clarify the license in the readme (r15534)<br
/> Multisite: Fix the delete_user meta capability (r15562)<br
/> Multisite: Force current_user_can_for_blog() to run map_meta_cap() even for super admins (#15122)<br
/> Multisite: Fix ms-files.php content type headers when requesting a URL with a query string (#14450)<br
/> Multisite: Fix the usage of the SUBDOMAIN_INSTALL constant for upgraded WordPress MU installs (#14536)</p></blockquote><p>The WordPress devs recommend to update the blog immediately even if no additional authors are registered on a blog.</p><p>I have updated around 20 WordPress blogs by now and there were no plugin incompatibilities or other issues related to the update.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/12/01/wordpress-3-02-security-update-released/feed/</wfw:commentRss> <slash:comments>9</slash:comments> </item> <item><title>WordPress 3.01 Released, Update Now</title><link>http://www.ghacks.net/2010/07/30/wordpress-3-01-released-update-now/</link> <comments>http://www.ghacks.net/2010/07/30/wordpress-3-01-released-update-now/#comments</comments> <pubDate>Thu, 29 Jul 2010 22:48:38 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[ghacks]]></category> <category><![CDATA[The Web]]></category> <category><![CDATA[blog]]></category> <category><![CDATA[blog software]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=28904</guid> <description><![CDATA[Nothing&#8217;s more refreshing than receiving a notification of a WordPress update the minuted before going to bed. WordPress updates are serious, most of the time. Not updating the blog immediately could leave it open for exploits, and malicious users could do many bad things with that new found power. WordPress 3.01 has been released a [...]]]></description> <content:encoded><![CDATA[<p>Nothing&#8217;s more refreshing than receiving a notification of a WordPress update the minuted before going to bed. WordPress updates are serious, most of the time. Not updating the blog immediately could leave it open for exploits, and malicious users could do many bad things with that new found power.</p><p>WordPress 3.01 has been released a few minutes ago. The update is maintenance related, according to the blog post <a
href="http://wordpress.org/news/2010/07/wordpress-3-0-1/">over</a> at the official WordPress website. The new version fixes 50 minor issues in the blogging platform. The only &#8211; somewhat &#8211; security / privacy related issue that was fixed was a bug that allowed logged in users to view trashed articles of other users.</p><p><span
id="more-28904"></span>WordPress admins who are interested in the bugs that have been fixed in the release can take a look at <a
href="http://core.trac.wordpress.org/query?status=closed&#038;group=resolution&#038;milestone=3.0.1">Buqtraq</a> which lists them all.</p><p>Everyone else can <a
href="http://wordpress.org/">download</a> the new version from the official website, or update the WordPress blog automatically from the admin dashboard. Updating the blog should be fast and smooth, considering the nature of the update. It is still advised to create a backup of the blog&#8217;s files and database before pressing the update button or starting the manual updating process.</p><p>Ghacks has been just updated, all my other blogs have to wait until the morning. Good night everyone.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/07/30/wordpress-3-01-released-update-now/feed/</wfw:commentRss> <slash:comments>8</slash:comments> </item> <item><title>WordPress 2.9.2 Released</title><link>http://www.ghacks.net/2010/02/16/wordpress-2-9-2-released/</link> <comments>http://www.ghacks.net/2010/02/16/wordpress-2-9-2-released/#comments</comments> <pubDate>Mon, 15 Feb 2010 22:02:42 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[The Web]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress update]]></category> <category><![CDATA[wordpress vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=23089</guid> <description><![CDATA[An update for the blogging script WordPress has just been released by the development team. The update fixes a security vulnerability that was previously reported by Thomas Mackenzie on his personal blog. The vulnerability affects all WordPress installations with the version number 2.9.0 or later. Previous WordPress installations are not affected by the vulnerability (but [...]]]></description> <content:encoded><![CDATA[<p>An update for the blogging script WordPress has just been released by the development team. The update fixes a security vulnerability that was previously reported <a
href="http://tmacuk.co.uk/">by</a> Thomas Mackenzie on his personal blog. The vulnerability affects all WordPress installations with the version number 2.9.0 or later. Previous WordPress installations are not affected by the vulnerability (but are insecure because of other reasons).</p><p>The vulnerability exploits a new feature that has been introduced in WordPress 2.9: the trash. The trash is a basic trashcan where deleted posts are placed so that they can be restored if they have been deleted by accident. This trash can be disabled but is activated by default on all WordPress 2.9 and later blogs.</p><p><span
id="more-23089"></span>Every logged in user, even those with the subscriber role, can access all deleted articles and posts that have been moved to the trash. This might not affect the majority of blogs as there need to be at least two registered users and at least one user that is not trusted by the administrator of the site.</p><p>In theory though anyone with a user account at the website can access the trashed articles regardless of which user wrote them.</p><p>The WordPress 2.9.2 patch fixes this exploit so that this is no longer possible. WordPress 2.9.2. <a
href="http://wordpress.org/news/2010/02/wordpress-2-9-2/">can be</a> downloaded from the official WordPress website. Users who have configured their blog for automatic updates can also update the blog from within the blog right away.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/02/16/wordpress-2-9-2-released/feed/</wfw:commentRss> <slash:comments>18</slash:comments> </item> <item><title>WordPress 2.9.1 Released</title><link>http://www.ghacks.net/2010/01/05/wordpress-2-9-1-released/</link> <comments>http://www.ghacks.net/2010/01/05/wordpress-2-9-1-released/#comments</comments> <pubDate>Tue, 05 Jan 2010 09:38:51 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Online Services]]></category> <category><![CDATA[blog]]></category> <category><![CDATA[blogging]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=22052</guid> <description><![CDATA[Less than three weeks after the release of the much awaited WordPress 2.9 release milestone comes WordPress 2.9.1, a release that was expected by many because of bugs that some WordPress webmasters encountered after upgrading to or installing WordPress 2.9. The most notable &#8211; and annoying bug &#8211; was that WordPress seemed to have problems [...]]]></description> <content:encoded><![CDATA[<p>Less than three weeks after the release of the much awaited WordPress 2.9 release milestone comes WordPress 2.9.1, a release that was expected by many because of bugs that some WordPress webmasters encountered after upgrading to or installing WordPress 2.9. The most notable &#8211; and annoying bug &#8211; was that WordPress seemed to have problems with scheduled posts and pages on some web hosts.</p><p>Scheduled posts would not be published at the time configured by the user but appear as missed in the list of posts forcing the webmaster to reschedule and hope for the best or to publish it manually.</p><p><span
id="more-22052"></span>WordPress 2.9.1 fixes this annoying bug and 23 others that are listed in WordPress Trac. Five of the bugs listed have been rated high while the majority received a normal rating. Several updates fix installation and upgrade issues that webmasters might have experienced. Webmasters with those issues might want to install or upgrade straight to WordPress 2.9.1 which might fix the issues experienced by those webmasters.</p><p>Our blogs have not picked up the new version of WordPress yet but it is likely that this will happen in the next few hours.</p><p>WordPress 2.9.1 can be downloaded at the official <a
href="http://wordpress.org/download/">WordPress</a> website. The list of bug fixes is available <a
href="http://core.trac.wordpress.org/query?status=closed&#038;group=resolution&#038;order=priority&#038;milestone=2.9.1&#038;resolution=fixed">here</a>.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/01/05/wordpress-2-9-1-released/feed/</wfw:commentRss> <slash:comments>7</slash:comments> </item> <item><title>WordPress 2.9 Released</title><link>http://www.ghacks.net/2009/12/19/wordpress-2-9-released/</link> <comments>http://www.ghacks.net/2009/12/19/wordpress-2-9-released/#comments</comments> <pubDate>Sat, 19 Dec 2009 10:15:14 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Software]]></category> <category><![CDATA[The Web]]></category> <category><![CDATA[blog]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress update]]></category> <category><![CDATA[wordpress upgrade]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=21577</guid> <description><![CDATA[The WordPress developers have released version 2.9 of their popular blogging script WordPress which can be downloaded from the official WordPress website. Users who have configured automatic updates can also upgrade to the new version of WordPress from within their blogs. It is however recommended to backup the files and database before initiating the update. [...]]]></description> <content:encoded><![CDATA[<p>The WordPress developers have released version 2.9 of their popular blogging script WordPress which can be downloaded from the official WordPress website. Users who have configured automatic updates can also upgrade to the new version of WordPress from within their blogs. It is however recommended to backup the files and database before initiating the update.</p><p>The new version comes with over 500 bug fixes, changes and enhancements which makes it a recommended download and install. Some of the new features include:</p><p><span
id="more-21577"></span><ul><li>Trashbin: Posts that are deleted are now moved to the trash instead of being deleted irrecoverably. It is possible to recover posts from the trash at a later time.</li><li>Image Editor: A basic image editor that can be used to edit, rotate, scale and crop images.</li><li>Batch plugin support: Update up to ten plugins at once.</li><li>Video Embeds: video embeds for popular sites have become just a tad easier as it is now possible to simply paste the url into the post which will be turned into an appropriate viewer by WordPress automatically.</li><li>Automatic database optimization which can be enabled by adding define(&#8216;WP_ALLOW_REPAIR&#8217;, true); to the WordPress config file.</li><li>Post Thumbnails options which can be used to display thumbnails in every post if the theme supports it.</li><li>Better SEO thanks to rel=canonical</li><li>Custom galleries with the ability to add pictures from several posts.</li></ul><p>The complete list of changes can be viewed at <a
href="http://core.trac.wordpress.org/query?status=closed&#038;milestone=2.9">WordPress Trac</a>. Happy upgrading!</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/12/19/wordpress-2-9-released/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>WordPress 2.8.6 Security Update</title><link>http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/</link> <comments>http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/#comments</comments> <pubDate>Thu, 12 Nov 2009 23:40:02 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[The Web]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress security]]></category> <category><![CDATA[wordpress update]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=18457</guid> <description><![CDATA[The WordPress developers have just released a security update for their blogging platform WordPress which raises the version of the software to 2.8.6. It is always recommended to update to a new version of WordPress as soon as possible and especially so for a security release. This release fixes two vulnerabilities that are only relevant [...]]]></description> <content:encoded><![CDATA[<p>The WordPress developers have just released a security update for their blogging platform WordPress which raises the version of the software to 2.8.6. It is always recommended to update to a new version of WordPress as soon as possible and especially so for a security release. This release fixes two vulnerabilities that are only relevant for multi-author blogs as they can only be exploited by registered, logged in users with posting rights. This security vulnerability is therefor not affecting the majority of WordPress blogs but those webmasters should nevertheless consider upgrading their blog software right away.</p><p><span
id="more-18457"></span><br
/><blockquote>The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch.  The second problem, discovered by Dawid Golunski, is an issue with sanitizing uploaded file names that can be exploited in certain Apache configurations. Thanks to Benjamin and Dawid for finding and reporting these.</p></blockquote><p>The upgrade is as usual available through various means with the two most popular ones being through an automatic update in the WordPress admin interface and the second trough a download from the <a
href="http://wordpress.org/download/">official</a> WordPress website. The first is faster and more comfortable while the second offers more control to the user especially if something goes wrong.</p><p>This WordPress update does not require an update of the WordPress database. It is however recommended to perform a backup of both the WordPress files on the web server and the MySQL database to be prepared if the update should fail for any reason.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/feed/</wfw:commentRss> <slash:comments>5</slash:comments> </item> <item><title>WordPress 2.8.5 Security Update</title><link>http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/</link> <comments>http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/#comments</comments> <pubDate>Wed, 21 Oct 2009 13:53:23 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[The Web]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress security]]></category> <category><![CDATA[wordpress update]]></category> <category><![CDATA[wordpress upgrade]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=17549</guid> <description><![CDATA[The WordPress developers have released version 2.8.5 of their popular blogging software. The version is considered a security upgrade and therefor mandatory for all WordPress blog owners who run their own WordPress blog (but not those running a blog at WordPress.com). The developers are calling this released a hardening release as it tightens WordPress security [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://www.ghacks.net/wp-content/uploads/2009/08/wordpress.gif" alt="wordpress" title="wordpress" width="166" height="142" class="alignleft size-full wp-image-15748" />The WordPress developers have released version 2.8.5 of their popular blogging software. The version is considered a security upgrade and therefor mandatory for all WordPress blog owners who run their own WordPress blog (but not those running a blog at WordPress.com). The developers are calling this released a hardening release as it tightens WordPress security to make WordPress blogs more secure than before. The release is also fixing a Trackback denial of service attack that is currently in the wild.</p><p>The most important changes in WordPress 2.8.5 are therefor:</p><ul><li>A fix for the Trackback Denial-of-Service attack that is currently being seen.</li><li>Removal of areas within the code where php code in variables was evaluated.</li><li>Switched the file upload functionality to be whitelisted for all users including Admins.</li><li>Retiring of the two importers of Tag data from old plugins.</li></ul><p><span
id="more-17549"></span>WordPress blogs are currently not announcing the new release. It is expected that this will change in the next hours so that the automatic update option becomes available for WordPress webmasters who use it to update their website. Webmasters who manually update their blog can <a
href="http://wordpress.org/">visit</a> the WordPress page to download the latest version of WordPress. Additional information about the security release are available in the blog <a
href="http://wordpress.org/news/2009/10/wordpress-2-8-5-hardening-release/">post</a> that announced the upgrade.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Computer Worm Attacks Not Updated WordPress Blogs</title><link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/</link> <comments>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/#comments</comments> <pubDate>Sun, 06 Sep 2009 09:07:43 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[The Web]]></category> <category><![CDATA[blog]]></category> <category><![CDATA[blogging]]></category> <category><![CDATA[computer work]]></category> <category><![CDATA[webmaster]]></category> <category><![CDATA[wordpress]]></category> <category><![CDATA[wordpress exploit]]></category> <category><![CDATA[wordpress update]]></category> <category><![CDATA[wordpress vulnerability]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=16060</guid> <description><![CDATA[A computer worm is currently in the wild that is attacking unpatched WordPress blogs. Unpatched meaning blogs that have not been updated by their administrators to the latest version of the popular blogging software. The worm exploits a security vulnerability in older versions of WordPress to create a user account, make some changes to the [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://www.ghacks.net/wp-content/uploads/2009/08/wordpress.gif" alt="wordpress" title="wordpress" width="166" height="142" class="alignleft size-full wp-image-15748" />A computer worm is currently in the wild that is attacking unpatched WordPress blogs. Unpatched meaning blogs that have not been updated by their administrators to the latest version of the popular blogging software. The worm exploits a security vulnerability in older versions of WordPress to create a user account, make some changes to the WordPress installation and to the permalink structure of the blog. It is therefor possible at first glance to see if a WordPress blog was hacked by the computer work. All that needs to be done is to look at the urls of the blog. If there is more than there should be the blog has been most likely fallen pray to the worm.</p><p><span
id="more-16060"></span>According to <a
href="http://mashable.com/2009/09/05/wordpress-attack/">Mashable</a> there are two clues that your blog has been successfully attacked by the computer worm:</p><blockquote><p>There are two clues that your WordPress site has been attacked.</p><p> There are strange additions to the pretty permalinks, such as example.com/category/post-title/%&#038;(%7B$%7Beval(base64_decode($_SERVER%5BHTTP_REFERER%5D))%7D%7D|.+)&#038;%/. The keywords are “eval” and “base64_decode.”</p><p> The second clue is that a “back door” was created by a “hidden” Administrator. Check your site users for “Administrator (2)” or a name you do not recognize. You will probably be unable to access that account.</p></blockquote><p>Webmasters are asked to update their blogs to the latest version of WordPress immediately. Those that have been hit by the computer worm should backup all files, export their settings, and do a clean install of WordPress. More help is <a
href="http://codex.wordpress.org/FAQ_My_site_was_hacked">offered</a> at the WordPress website.</p><p><strong>Rant:</strong></p><p>It&#8217;s Sunday and it is time for a little rant. Webmasters who do not update their blogs as soon as a new version of their blogging software is released are acting stupid. A WordPress update usually takes less than ten minutes and ensures that the blog and server is protected from attacks like these. Webmasters who do not have the time to perform these updates should consider switching to a hosted blogging platform like that at Blogger or WordPress.com. The automatic update option that has been introduced in recent WordPress versions makes it even easier to update the blog as soon as a new version is released. Webmasters who cannot do this should not operate a self hosted blog, period.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/feed/</wfw:commentRss> <slash:comments>25</slash:comments> </item> </channel> </rss>
