<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; wordpress update</title>
	<atom:link href="http://www.ghacks.net/tag/wordpress-update/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 24 Nov 2009 23:31:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Wordpress 2.8.6 Security Update</title>
		<link>http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/</link>
		<comments>http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/#comments</comments>
		<pubDate>Thu, 12 Nov 2009 23:40:02 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[The Web]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress 2.8.6]]></category>
		<category><![CDATA[wordpress security]]></category>
		<category><![CDATA[wordpress update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=18457</guid>
		<description><![CDATA[The Wordpress developers have just released a security update for their blogging platform Wordpress which raises the version of the software to 2.8.6. It is always recommended to update to a new version of Wordpress as soon as possible and especially so for a security release. This release fixes two vulnerabilities that are only relevant [...]]]></description>
			<content:encoded><![CDATA[<p>The Wordpress developers have just released a security update for their blogging platform Wordpress which raises the version of the software to 2.8.6. It is always recommended to update to a new version of Wordpress as soon as possible and especially so for a security release. This release fixes two vulnerabilities that are only relevant for multi-author blogs as they can only be exploited by registered, logged in users with posting rights. This security vulnerability is therefor not affecting the majority of Wordpress blogs but those webmasters should nevertheless consider upgrading their blog software right away.</p>
<p><span id="more-18457"></span><br />
<blockquote>The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch.  The second problem, discovered by Dawid Golunski, is an issue with sanitizing uploaded file names that can be exploited in certain Apache configurations. Thanks to Benjamin and Dawid for finding and reporting these.</p></blockquote>
<p>The upgrade is as usual available through various means with the two most popular ones being through an automatic update in the Wordpress admin interface and the second trough a download from the <a href="http://wordpress.org/download/">official</a> Wordpress website. The first is faster and more comfortable while the second offers more control to the user especially if something goes wrong.</p>
<p>This Wordpress update does not require an update of the Wordpress database. It is however recommended to perform a backup of both the Wordpress files on the web server and the MySQL database to be prepared if the update should fail for any reason.</p>

	Tags: <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-2-8-6/" title="wordpress 2.8.6" rel="tag">wordpress 2.8.6</a>, <a href="http://www.ghacks.net/tag/wordpress-security/" title="wordpress security" rel="tag">wordpress security</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/" title="Wordpress 2.8.5 Security Update (October 21, 2009)">Wordpress 2.8.5 Security Update</a> (4)</li>
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/11/25/wordpress-265-security-update/" title="Wordpress 2.6.5 Security Update (November 25, 2008)">Wordpress 2.6.5 Security Update</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/08/15/wordpress-261-released/" title="Wordpress 2.6.1 released (August 15, 2008)">Wordpress 2.6.1 released</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/08/04/wordpress-2-8-3/" title="Wordpress 2.8.3 (August 4, 2009)">Wordpress 2.8.3</a> (1)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.8.5 Security Update</title>
		<link>http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/</link>
		<comments>http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 13:53:23 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[The Web]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress security]]></category>
		<category><![CDATA[wordpress update]]></category>
		<category><![CDATA[wordpress upgrade]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=17549</guid>
		<description><![CDATA[The Wordpress developers have released version 2.8.5 of their popular blogging software. The version is considered a security upgrade and therefor mandatory for all Wordpress blog owners who run their own Wordpress blog (but not those running a blog at Wordpress.com). The developers are calling this released a hardening release as it tightens Wordpress security [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/08/wordpress.gif" alt="wordpress" title="wordpress" width="166" height="142" class="alignleft size-full wp-image-15748" />The Wordpress developers have released version 2.8.5 of their popular blogging software. The version is considered a security upgrade and therefor mandatory for all Wordpress blog owners who run their own Wordpress blog (but not those running a blog at Wordpress.com). The developers are calling this released a hardening release as it tightens Wordpress security to make Wordpress blogs more secure than before. The release is also fixing a Trackback denial of service attack that is currently in the wild.</p>
<p>The most important changes in Wordpress 2.8.5 are therefor:</p>
<ul>
<li>A fix for the Trackback Denial-of-Service attack that is currently being seen.</li>
<li>Removal of areas within the code where php code in variables was evaluated.</li>
<li>Switched the file upload functionality to be whitelisted for all users including Admins.</li>
<li>Retiring of the two importers of Tag data from old plugins.</li>
</ul>
<p><span id="more-17549"></span>Wordpress blogs are currently not announcing the new release. It is expected that this will change in the next hours so that the automatic update option becomes available for Wordpress webmasters who use it to update their website. Webmasters who manually update their blog can <a href="http://wordpress.org/">visit</a> the Wordpress page to download the latest version of Wordpress. Additional information about the security release are available in the blog <a href="http://wordpress.org/development/2009/10/wordpress-2-8-5-hardening-release/">post</a> that announced the upgrade.</p>

	Tags: <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-security/" title="wordpress security" rel="tag">wordpress security</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a>, <a href="http://www.ghacks.net/tag/wordpress-upgrade/" title="wordpress upgrade" rel="tag">wordpress upgrade</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/" title="Wordpress 2.8.6 Security Update (November 13, 2009)">Wordpress 2.8.6 Security Update</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/11/25/wordpress-265-security-update/" title="Wordpress 2.6.5 Security Update (November 25, 2008)">Wordpress 2.6.5 Security Update</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/08/15/wordpress-261-released/" title="Wordpress 2.6.1 released (August 15, 2008)">Wordpress 2.6.1 released</a> (1)</li>
	<li><a href="http://www.ghacks.net/2007/09/25/dont-upgrade-to-wordpress-23-yet/" title="Don&#8217;t upgrade to Wordpress 2.3 yet (September 25, 2007)">Don&#8217;t upgrade to Wordpress 2.3 yet</a> (3)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Computer Worm Attacks Not Updated Wordpress Blogs</title>
		<link>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/</link>
		<comments>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/#comments</comments>
		<pubDate>Sun, 06 Sep 2009 09:07:43 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[blogging]]></category>
		<category><![CDATA[computer work]]></category>
		<category><![CDATA[webmaster]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress exploit]]></category>
		<category><![CDATA[wordpress update]]></category>
		<category><![CDATA[wordpress vulnerability]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=16060</guid>
		<description><![CDATA[A computer worm is currently in the wild that is attacking unpatched Wordpress blogs. Unpatched meaning blogs that have not been updated by their administrators to the latest version of the popular blogging software. The worm exploits a security vulnerability in older versions of Wordpress to create a user account, make some changes to the [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/08/wordpress.gif" alt="wordpress" title="wordpress" width="166" height="142" class="alignleft size-full wp-image-15748" />A computer worm is currently in the wild that is attacking unpatched Wordpress blogs. Unpatched meaning blogs that have not been updated by their administrators to the latest version of the popular blogging software. The worm exploits a security vulnerability in older versions of Wordpress to create a user account, make some changes to the Wordpress installation and to the permalink structure of the blog. It is therefor possible at first glance to see if a Wordpress blog was hacked by the computer work. All that needs to be done is to look at the urls of the blog. If there is more than there should be the blog has been most likely fallen pray to the worm.</p>
<p><span id="more-16060"></span>According to <a href="http://mashable.com/2009/09/05/wordpress-attack/">Mashable</a> there are two clues that your blog has been successfully attacked by the computer worm:</p>
<blockquote><p>There are two clues that your WordPress site has been attacked.</p>
<p>    There are strange additions to the pretty permalinks, such as example.com/category/post-title/%&#038;(%7B$%7Beval(base64_decode($_SERVER%5BHTTP_REFERER%5D))%7D%7D|.+)&#038;%/. The keywords are “eval” and “base64_decode.”</p>
<p>    The second clue is that a “back door” was created by a “hidden” Administrator. Check your site users for “Administrator (2)” or a name you do not recognize. You will probably be unable to access that account.</p></blockquote>
<p>Webmasters are asked to update their blogs to the latest version of Wordpress immediately. Those that have been hit by the computer worm should backup all files, export their settings, and do a clean install of Wordpress. More help is <a href="http://codex.wordpress.org/FAQ_My_site_was_hacked">offered</a> at the Wordpress website.</p>
<p><strong>Rant:</strong></p>
<p>It&#8217;s Sunday and it is time for a little rant. Webmasters who do not update their blogs as soon as a new version of their blogging software is released are acting stupid. A Wordpress update usually takes less than ten minutes and ensures that the blog and server is protected from attacks like these. Webmasters who do not have the time to perform these updates should consider switching to a hosted blogging platform like that at Blogger or Wordpress.com. The automatic update option that has been introduced in recent Wordpress versions makes it even easier to update the blog as soon as a new version is released. Webmasters who cannot do this should not operate a self hosted blog, period.</p>

	Tags: <a href="http://www.ghacks.net/tag/blog/" title="blog" rel="tag">blog</a>, <a href="http://www.ghacks.net/tag/blogging/" title="blogging" rel="tag">blogging</a>, <a href="http://www.ghacks.net/tag/computer-work/" title="computer work" rel="tag">computer work</a>, <a href="http://www.ghacks.net/tag/webmaster/" title="webmaster" rel="tag">webmaster</a>, <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-exploit/" title="wordpress exploit" rel="tag">wordpress exploit</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a>, <a href="http://www.ghacks.net/tag/wordpress-vulnerability/" title="wordpress vulnerability" rel="tag">wordpress vulnerability</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/08/11/wordpress-remote-admin-password-reset-vulnerability/" title="Wordpress Remote Admin Password Reset Vulnerability (August 11, 2009)">Wordpress Remote Admin Password Reset Vulnerability</a> (13)</li>
	<li><a href="http://www.ghacks.net/2009/08/12/wordpress-2-8-4-security-update/" title="Wordpress 2.8.4 Security Update (August 12, 2009)">Wordpress 2.8.4 Security Update</a> (7)</li>
	<li><a href="http://www.ghacks.net/2009/06/11/wordpress-2-8/" title="Wordpress 2.8 (June 11, 2009)">Wordpress 2.8</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/08/04/wordpress-2-8-3/" title="Wordpress 2.8.3 (August 4, 2009)">Wordpress 2.8.3</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.8.3</title>
		<link>http://www.ghacks.net/2009/08/04/wordpress-2-8-3/</link>
		<comments>http://www.ghacks.net/2009/08/04/wordpress-2-8-3/#comments</comments>
		<pubDate>Mon, 03 Aug 2009 22:37:26 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[blog update]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress 2.8.3]]></category>
		<category><![CDATA[wordpress update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=15018</guid>
		<description><![CDATA[The Wordpress developers have released version 2.8.3 of the popular blogging script. The update is a security update and it is therefor recommended to update the Wordpress installation immediately to protect the data and web server. Upgrades are as usually available directly from within the Wordpress admin interface or by downloading the new version of [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/04/wordpress.png" alt="wordpress" title="wordpress" width="128" height="128" class="alignleft size-full wp-image-11834" />The Wordpress developers have released version 2.8.3 of the popular blogging script. The update is a security update and it is therefor recommended to update the Wordpress installation immediately to protect the data and web server. Upgrades are as usually available directly from within the Wordpress admin interface or by downloading the new version of Wordpress from the website and installing it manually on the server.</p>
<p>The upgrade fixes a few security issues that have been overlooked in the Wordpress 2.8.1 release but discovered by security researchers in the Wordpress community. </p>
<p><span id="more-15018"></span><br />
<blockquote>Unfortunately, I missed some places when fixing the privilege escalation issues for 2.8.1.  Luckily, the entire WordPress community has our backs.  Several folks in the community dug deeper and discovered areas that were overlooked.  With their help, the remaining issues are fixed in 2.8.3.  Since this is a security release, upgrading is highly recommended.</p></blockquote>
<p>Point your web browser to the official <a href="http://wordpress.org/download/">Wordpress</a> download page to download the release if you want to perform a manual upgrade. </p>

	Tags: <a href="http://www.ghacks.net/tag/blog/" title="blog" rel="tag">blog</a>, <a href="http://www.ghacks.net/tag/blog-update/" title="blog update" rel="tag">blog update</a>, <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-2-8-3/" title="wordpress 2.8.3" rel="tag">wordpress 2.8.3</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/06/11/wordpress-2-8/" title="Wordpress 2.8 (June 11, 2009)">Wordpress 2.8</a> (5)</li>
	<li><a href="http://www.ghacks.net/2008/12/11/wordpress-27/" title="Wordpress 2.7 (December 11, 2008)">Wordpress 2.7</a> (7)</li>
	<li><a href="http://www.ghacks.net/2008/11/25/wordpress-265-security-update/" title="Wordpress 2.6.5 Security Update (November 25, 2008)">Wordpress 2.6.5 Security Update</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/08/15/wordpress-261-released/" title="Wordpress 2.6.1 released (August 15, 2008)">Wordpress 2.6.1 released</a> (1)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/08/04/wordpress-2-8-3/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.8.2 Security Patch</title>
		<link>http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/</link>
		<comments>http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 10:00:25 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[blogging platform]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress 2.8.2]]></category>
		<category><![CDATA[wordpress security]]></category>
		<category><![CDATA[wordpress update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=14549</guid>
		<description><![CDATA[A new version of the popular blogging platform Wordpress was released just a few minutes ago. It is an unexpected upgrade considering that the last Wordpress update was less than two weeks ago. The new update fixes a security vulnerability that affects all but the latest version of Wordpress.
The XSS vulnerability could be used to [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/04/wordpress.png" alt="wordpress" title="wordpress" width="128" height="128" class="alignleft size-full wp-image-11834" />A new version of the popular blogging platform Wordpress was released just a few minutes ago. It is an unexpected upgrade considering that the last Wordpress update was less than two weeks ago. The new update fixes a security vulnerability that affects all but the latest version of Wordpress.</p>
<p><a href="http://wordpress.org/development/2009/07/wordpress-2-8-2/">The</a> XSS vulnerability could be used to create comment author urls that would redirect the system administrator away from the blog&#8217;s website to another site to exploit the situation. Wordpress webmasters are encouraged to update their blogs as soon as possible to patch the security vulnerability.</p>
<p><span id="more-14549"></span>Updates are available directly from within the Wordpress interface if the correct server login information are supplied or by updating the traditional way which would mean to <a href="http://wordpress.org/download/">download</a> the Wordpress release from the Wordpress website, upload it to the web server and run the upgrade command manually. The release information should also be displayed prominently in the Wordpress admin interface with a link to the automatic update script of Wordpress.</p>

	Tags: <a href="http://www.ghacks.net/tag/blog/" title="blog" rel="tag">blog</a>, <a href="http://www.ghacks.net/tag/blogging-platform/" title="blogging platform" rel="tag">blogging platform</a>, <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-2-8-2/" title="wordpress 2.8.2" rel="tag">wordpress 2.8.2</a>, <a href="http://www.ghacks.net/tag/wordpress-security/" title="wordpress security" rel="tag">wordpress security</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/06/11/wordpress-2-8/" title="Wordpress 2.8 (June 11, 2009)">Wordpress 2.8</a> (5)</li>
	<li><a href="http://www.ghacks.net/2008/11/25/wordpress-265-security-update/" title="Wordpress 2.6.5 Security Update (November 25, 2008)">Wordpress 2.6.5 Security Update</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/08/15/wordpress-261-released/" title="Wordpress 2.6.1 released (August 15, 2008)">Wordpress 2.6.1 released</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/" title="Wordpress 2.8.6 Security Update (November 13, 2009)">Wordpress 2.8.6 Security Update</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/" title="Wordpress 2.8.5 Security Update (October 21, 2009)">Wordpress 2.8.5 Security Update</a> (4)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.8</title>
		<link>http://www.ghacks.net/2009/06/11/wordpress-2-8/</link>
		<comments>http://www.ghacks.net/2009/06/11/wordpress-2-8/#comments</comments>
		<pubDate>Thu, 11 Jun 2009 09:59:06 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[The Web]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[blogging]]></category>
		<category><![CDATA[blogging platform]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress 2.8]]></category>
		<category><![CDATA[wordpress update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2009/06/11/wordpress-2-8/</guid>
		<description><![CDATA[A new version of the popular blogging script Wordpress has been released by the developers yesterday. Wordpress 2.8 is the latest stable release of the blogging platform and webmasters are encouraged to upgrade their blogs as soon as possible to benefit from the changes in that version. The update adds a multitude of features and [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/06/wordpress28.jpg" alt="wordpress28" title="wordpress28" width="240" height="70" class="alignleft size-full wp-image-13438" />A new version of the popular blogging script Wordpress has been released by the developers yesterday. Wordpress 2.8 is the latest stable release of the blogging platform and webmasters are encouraged to upgrade their blogs as soon as possible to benefit from the changes in that version. The update adds a multitude of features and improvements to Wordpress which are mostly noticeable in the admin area of the blog.</p>
<p>Some changes that Wordpress admins will notice right away are speed improvements in the admin interface and the ability to change more aspects of the layout than before. Wordpress will for instance automatically adjust the layout according to the screen size of the web browser window with options to change the amount of columns and what is being displayed on the screen.</p>
<p><span id="more-13440"></span><img src="http://www.ghacks.net/wp-content/uploads/2009/06/wordpress28_admin-500x333.jpg" alt="wordpress28_admin" title="wordpress28_admin" width="500" height="333" class="alignnone size-medium wp-image-13439" /></p>
<p>It is now possible to remove or add information when viewing posts, pages or comments in the admin interface with the additional option to change the number of items that are displayed on the screen. It is now therefor possible to change the default number of comments that are displayed on screen which could have been achieved before only by hacking system files.</p>
<p>Other improvements include a new theme installer which allows the webmaster to search for and install themes right from the Wordpress admin interface without leaving the website. This is a similar feature to the automatic plugin installation that was added in earlier versions.</p>
<p>The <a href="http://codex.wordpress.org/Version_2.8">Wordpress Codex</a> contains a list of all changes and additions that have been added to Wordpress 2.8. The new version can be downloaded from the main <a href="http://wordpress.org/download/">Wordpress</a> site.</p>

	Tags: <a href="http://www.ghacks.net/tag/blog/" title="blog" rel="tag">blog</a>, <a href="http://www.ghacks.net/tag/blogging/" title="blogging" rel="tag">blogging</a>, <a href="http://www.ghacks.net/tag/blogging-platform/" title="blogging platform" rel="tag">blogging platform</a>, <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-2-8/" title="wordpress 2.8" rel="tag">wordpress 2.8</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/09/06/computer-worm-attacks-not-updated-wordpress-blogs/" title="Computer Worm Attacks Not Updated Wordpress Blogs (September 6, 2009)">Computer Worm Attacks Not Updated Wordpress Blogs</a> (20)</li>
	<li><a href="http://www.ghacks.net/2009/08/04/wordpress-2-8-3/" title="Wordpress 2.8.3 (August 4, 2009)">Wordpress 2.8.3</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/12/11/wordpress-27/" title="Wordpress 2.7 (December 11, 2008)">Wordpress 2.7</a> (7)</li>
	<li><a href="http://www.ghacks.net/2008/11/25/wordpress-265-security-update/" title="Wordpress 2.6.5 Security Update (November 25, 2008)">Wordpress 2.6.5 Security Update</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/06/11/wordpress-2-8/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.7.1 Update</title>
		<link>http://www.ghacks.net/2009/02/11/wordpress-271-update/</link>
		<comments>http://www.ghacks.net/2009/02/11/wordpress-271-update/#comments</comments>
		<pubDate>Tue, 10 Feb 2009 22:59:07 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[software]]></category>
		<category><![CDATA[blog software]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress 2.7.1]]></category>
		<category><![CDATA[wordpress blog]]></category>
		<category><![CDATA[wordpress bugs]]></category>
		<category><![CDATA[wordpress update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=10460</guid>
		<description><![CDATA[Seems the Wordpress developers have finally released a new version of the free blog software. The update to Wordpress 2.7.1 (from 2.7) is a maintenance release which fixes 68 tickets. It is therefor a recommended upgrade and should be applied by Wordpress webmasters as soon as possible. The Wordpress tracker which is mentioned on the [...]]]></description>
			<content:encoded><![CDATA[<p>Seems the Wordpress developers have finally released a new version of the free blog software. The update to Wordpress 2.7.1 (from 2.7) is a maintenance release which fixes 68 tickets. It is therefor a recommended upgrade and should be applied by Wordpress webmasters as soon as possible. The Wordpress tracker which is mentioned on the update page is currently unavailable which is probably due to the release announcement which is visible for every admin in the Wordpress interface.</p>
<p>You can download the latest version of <a href="http://wordpress.org/development/2009/02/wordpress-271/">Wordpress</a> from the official website or apply the upgrade manually in the Wordpress interface. You can take a look at in depth file changes by following <a href="http://trac.wordpress.org/changeset?old_path=tags%2F2.7&#038;old=10539&#038;new_path=tags%2F2.7.1&#038;new=10539">this</a> link or at the 68 tickets that have been closed <a href="http://trac.wordpress.org/query?status=closed&#038;milestone=2.7.1&#038;resolution=fixed&#038;order=priority">here</a>.</p>
<p>The update includes six tickets with a high rating and more than 50 rated as normal. While the update does not list many security fixes it is still recommended to update as soon as possible. The update will not alter the database and should not break anything including plugins or themes.</p>
<p><span id="more-10460"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/blog-software/" title="blog software" rel="tag">blog software</a>, <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-271/" title="wordpress 2.7.1" rel="tag">wordpress 2.7.1</a>, <a href="http://www.ghacks.net/tag/wordpress-blog/" title="wordpress blog" rel="tag">wordpress blog</a>, <a href="http://www.ghacks.net/tag/wordpress-bugs/" title="wordpress bugs" rel="tag">wordpress bugs</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/11/25/wordpress-265-security-update/" title="Wordpress 2.6.5 Security Update (November 25, 2008)">Wordpress 2.6.5 Security Update</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/04/25/wordpress-251-released/" title="Wordpress 2.5.1 released (April 25, 2008)">Wordpress 2.5.1 released</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/02/02/wordpress-your-attempt-to-edit-this-post-has-failed/" title="Wordpress: Your attempt to edit this post has failed (February 2, 2009)">Wordpress: Your attempt to edit this post has failed</a> (8)</li>
	<li><a href="http://www.ghacks.net/2008/07/27/wordpress-issues/" title="Wordpress Issues (July 27, 2008)">Wordpress Issues</a> (16)</li>
	<li><a href="http://www.ghacks.net/2007/12/01/wordpress-incorrect-password/" title="Wordpress Incorrect Password (December 1, 2007)">Wordpress Incorrect Password</a> (2)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/02/11/wordpress-271-update/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.7</title>
		<link>http://www.ghacks.net/2008/12/11/wordpress-27/</link>
		<comments>http://www.ghacks.net/2008/12/11/wordpress-27/#comments</comments>
		<pubDate>Thu, 11 Dec 2008 11:26:44 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[The Web]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[blogging software]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress 2.7]]></category>
		<category><![CDATA[wordpress update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=8906</guid>
		<description><![CDATA[The Wordpress team has published version 2.7 of Wordpress yesterday. The first thing that users will notice is the new administration interface which was completely redone to optimize processes. The development team claims that nearly every task in Wordpress 2.7 will take fewer clicks than it took in previous versions of the blogging platform.
The development [...]]]></description>
			<content:encoded><![CDATA[<p>The Wordpress team has published version 2.7 of Wordpress yesterday. The first thing that users will notice is the new administration interface which was completely redone to optimize processes. The development team claims that nearly every task in <a href="http://codex.wordpress.org/Version_2.7">Wordpress 2.7</a> will take fewer clicks than it took in previous versions of the blogging platform.</p>
<p>The development focus was usability as Wordpress 2.7 brings in a few exciting new features to the table. The long awaited option to moderate comments from the admin interface, mass editing of posts or automatic upgrades of plugins and the blog software itself are just a few of the new features.</p>
<p>Another new and exciting option is the ability to remove and position elements on the screen. This streamlines the Wordpress admin interface quite a bit by bringing the needed elements closer together while removing everything that is not needed. Well, almost everything. Some elements cannot be removed obviously like the post form.</p>
<p><span id="more-8906"></span>It will take some time getting used to the new Wordpress admin interface as it moves the menu entries from the header to the left menu.</p>
<p>The update should not pose to many difficulties. The only problem that you can encounter are plugin incompatibilities. The Simple Tags plugin was one out of a dozen plugins that was not working with Wordpress and you might have noticed display problems here at Ghacks earlier thanks to that. There is however an easy temporary fix for that to make the plugin compatible.</p>
<p>All that needs to be done is to edit the simple-tags.php file. Look for the line</p>
<p><code>if (version_compare($wp_version, '2.5', '>='))</code></p>
<p>and replace it with the following</p>
<p><code>if ( strpos($wp_version, '2.5') !== false || strpos($wp_version, '2.6') !== false )</code></p>
<p>This should ensure compatibility.</p>

	Tags: <a href="http://www.ghacks.net/tag/blog/" title="blog" rel="tag">blog</a>, <a href="http://www.ghacks.net/tag/blogging-software/" title="blogging software" rel="tag">blogging software</a>, <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-27/" title="wordpress 2.7" rel="tag">wordpress 2.7</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/08/04/wordpress-2-8-3/" title="Wordpress 2.8.3 (August 4, 2009)">Wordpress 2.8.3</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/06/11/wordpress-2-8/" title="Wordpress 2.8 (June 11, 2009)">Wordpress 2.8</a> (5)</li>
	<li><a href="http://www.ghacks.net/2008/11/25/wordpress-265-security-update/" title="Wordpress 2.6.5 Security Update (November 25, 2008)">Wordpress 2.6.5 Security Update</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/08/15/wordpress-261-released/" title="Wordpress 2.6.1 released (August 15, 2008)">Wordpress 2.6.1 released</a> (1)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/12/11/wordpress-27/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.6.5 Security Update</title>
		<link>http://www.ghacks.net/2008/11/25/wordpress-265-security-update/</link>
		<comments>http://www.ghacks.net/2008/11/25/wordpress-265-security-update/#comments</comments>
		<pubDate>Tue, 25 Nov 2008 21:23:19 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[blog software]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[Wordpress 2.6.5]]></category>
		<category><![CDATA[wordpress blog]]></category>
		<category><![CDATA[wordpress security]]></category>
		<category><![CDATA[wordpress update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=8541</guid>
		<description><![CDATA[The Wordpress development team has released version 2.6.5 of the blogging plattform for download. The release fixes one security update and three bugs and can be downloaded from the official Wordpress website.
Alternatively only the files wp-includes/feed.php and wp-includes/version.php can be copied from the new release over the old files to update the blog. The security [...]]]></description>
			<content:encoded><![CDATA[<p>The Wordpress development team has released version 2.6.5 of the blogging plattform for download. The release fixes one security update and three bugs and can be <a href="http://wordpress.org/download/">downloaded</a> from the official Wordpress website.</p>
<p>Alternatively only the files wp-includes/feed.php and wp-includes/version.php can be copied from the new release over the old files to update the blog. The security vulnerability is unlikely to affect a large number of Wordpress blogs though as it only only affects IP-based virtual servers running on Apache 2.x.</p>
<p>There might also be some confusion about the versioning of Wordpress. The last official Wordpress version was Wordpress 2.6.3. Wordpress 2.6.4 was skipped because of a fake malicious release that made its round. The official new release is therefor Wordpress 2.6.5.</p>
<p><span id="more-8541"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/blog/" title="blog" rel="tag">blog</a>, <a href="http://www.ghacks.net/tag/blog-software/" title="blog software" rel="tag">blog software</a>, <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-265/" title="Wordpress 2.6.5" rel="tag">Wordpress 2.6.5</a>, <a href="http://www.ghacks.net/tag/wordpress-blog/" title="wordpress blog" rel="tag">wordpress blog</a>, <a href="http://www.ghacks.net/tag/wordpress-security/" title="wordpress security" rel="tag">wordpress security</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/02/11/wordpress-271-update/" title="Wordpress 2.7.1 Update (February 11, 2009)">Wordpress 2.7.1 Update</a> (3)</li>
	<li><a href="http://www.ghacks.net/2008/08/15/wordpress-261-released/" title="Wordpress 2.6.1 released (August 15, 2008)">Wordpress 2.6.1 released</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/04/25/wordpress-251-released/" title="Wordpress 2.5.1 released (April 25, 2008)">Wordpress 2.5.1 released</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/02/02/wordpress-your-attempt-to-edit-this-post-has-failed/" title="Wordpress: Your attempt to edit this post has failed (February 2, 2009)">Wordpress: Your attempt to edit this post has failed</a> (8)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/11/25/wordpress-265-security-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.6.1 released</title>
		<link>http://www.ghacks.net/2008/08/15/wordpress-261-released/</link>
		<comments>http://www.ghacks.net/2008/08/15/wordpress-261-released/#comments</comments>
		<pubDate>Fri, 15 Aug 2008 12:00:59 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Online Services]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress security]]></category>
		<category><![CDATA[wordpress update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=6187</guid>
		<description><![CDATA[A new version of Wordpress has been released today and I&#8217;m currently in the process of updating all of my Wordpress blogs with the new version. That&#8217;s always a lot of work because I tend to prefer a manual update and not the automatic option that was implemented into Wordpress a while ago.
Over 60 fixes [...]]]></description>
			<content:encoded><![CDATA[<p>A new version of <a href="http://wordpress.org/development/2008/08/wordpress-261/">Wordpress</a> has been released today and I&#8217;m currently in the process of updating all of my Wordpress blogs with the new version. That&#8217;s always a lot of work because I tend to prefer a manual update and not the automatic option that was implemented into Wordpress a while ago.</p>
<p>Over 60 fixes have been introduced in the new Wordpress version, several of them critical and some security related. You can check out the complete list of fixes in Wordpress 2.6.1 by following the link to <a href="http://trac.wordpress.org/query?status=closed&#038;milestone=2.6.1&#038;resolution=fixed&#038;order=priority&#038;desc=1">Wordpress Trac</a>.</p>
<p>I&#8217;m usually not that interested in what has been fixed than to apply the updates to all of my blogs immediately. It does not look like as if new features have been introduced in Wordpress 2.6.1, more of a bug fix release it seems.</p>
<p><span id="more-6187"></span>The next big release will be Wordpress 2.7 which will introduce several new features and options to Wordpress. Looking forward to that. It is however recommended to update the blog as soon as possible.</p>

	Tags: <a href="http://www.ghacks.net/tag/blog/" title="blog" rel="tag">blog</a>, <a href="http://www.ghacks.net/tag/website/" title="website" rel="tag">website</a>, <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-security/" title="wordpress security" rel="tag">wordpress security</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/11/25/wordpress-265-security-update/" title="Wordpress 2.6.5 Security Update (November 25, 2008)">Wordpress 2.6.5 Security Update</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/08/05/zoundry-raven-portable-blog-editor/" title="Zoundry Raven portable Blog Editor (August 5, 2008)">Zoundry Raven portable Blog Editor</a> (6)</li>
	<li><a href="http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/" title="Wordpress 2.8.6 Security Update (November 13, 2009)">Wordpress 2.8.6 Security Update</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/" title="Wordpress 2.8.5 Security Update (October 21, 2009)">Wordpress 2.8.5 Security Update</a> (4)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/08/15/wordpress-261-released/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.6</title>
		<link>http://www.ghacks.net/2008/07/15/wordpress-26/</link>
		<comments>http://www.ghacks.net/2008/07/15/wordpress-26/#comments</comments>
		<pubDate>Tue, 15 Jul 2008 08:11:40 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[The Web]]></category>
		<category><![CDATA[ghacks]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=5329</guid>
		<description><![CDATA[The Wordpress developers have released version 2.6 of their blogging plattform almost one month ahead of schedule and while some users might be excited to update their blogs and test the new features I&#8217;m always a bit taken back by those updates because it means that I have to spend a few hours updating my [...]]]></description>
			<content:encoded><![CDATA[<p>The Wordpress developers have released version 2.6 of their blogging plattform almost one month ahead of schedule and while some users might be excited to update their blogs and test the new features I&#8217;m always a bit taken back by those updates because it means that I have to spend a few hours updating my blogs to the newest version.</p>
<p><a href="http://wordpress.org/development/2008/07/wordpress-26-tyner/">Wordpress 2.6</a> introduces quite a few new features and some of them do sound interesting. They introduce revisions in this new Wordpress version which gives the user the option to restore and compare previous revisions of a text. Gears is another interesting feature that might especially appeal to users with slower connections. For now Gears is being used to store data in a local cache on the users&#8217; computer to speed up the Wordpress blog.</p>
<p>The most appealing change for me is without doubt the new plugin interface which finally divides active and inactive plugins, something that I wanted for years.</p>
<p><span id="more-5329"></span> <embed src="http://v.wordpress.com/mARhRBcT/fmt_std" type="application/x-shockwave-flash" width="400" height="250" flashvars="blog_domain=http://wordpress.org/development/2008/07/wordpress-26/&#038;width=400&#038;height=250"></embed>  </p>
<p>There have been many minor changes as well. A bookmarklet called Post It that can be used to embed objects, like text, videos or images, from a website directly into a Wordpress post that opens in a new window, a word count, the ability to force SSL, shift-click selection of checkboxes, editor updates and customizable default avatars.</p>
<p>I&#8217;ll be busy the next few hours updating my blogs and websites with this new version. The developers claim that there should not be any troubles updating to that version. We will see how it goes.</p>

	Tags: <a href="http://www.ghacks.net/tag/blog/" title="blog" rel="tag">blog</a>, <a href="http://www.ghacks.net/tag/ghacks/" title="ghacks" rel="tag">ghacks</a>, <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/08/04/wordpress-2-8-3/" title="Wordpress 2.8.3 (August 4, 2009)">Wordpress 2.8.3</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/06/11/wordpress-2-8/" title="Wordpress 2.8 (June 11, 2009)">Wordpress 2.8</a> (5)</li>
	<li><a href="http://www.ghacks.net/2008/12/11/wordpress-27/" title="Wordpress 2.7 (December 11, 2008)">Wordpress 2.7</a> (7)</li>
	<li><a href="http://www.ghacks.net/2008/11/25/wordpress-265-security-update/" title="Wordpress 2.6.5 Security Update (November 25, 2008)">Wordpress 2.6.5 Security Update</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/07/15/wordpress-26/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.5.1 released</title>
		<link>http://www.ghacks.net/2008/04/25/wordpress-251-released/</link>
		<comments>http://www.ghacks.net/2008/04/25/wordpress-251-released/#comments</comments>
		<pubDate>Fri, 25 Apr 2008 17:51:14 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[The Web]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[blog software]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=3918</guid>
		<description><![CDATA[A new version of Wordpress was released today that includes over 70 fixes including several important security fixes. The security fixes affect the files wp-includes/pluggable.php, wp-admin/includes/media.php, and wp-admin/media.php which can be downloaded separately if the full Wordpress update is not desired yet. Webmasters who ran into problems with the new way of uploading media files [...]]]></description>
			<content:encoded><![CDATA[<p>A new version of Wordpress was released today that includes over 70 fixes including several important security fixes. The security fixes affect the files wp-includes/pluggable.php, wp-admin/includes/media.php, and wp-admin/media.php which can be downloaded separately if the full Wordpress update is not desired yet. Webmasters who ran into problems with the new way of uploading media files will be reluctant to note that this issue has been fixed in Wordpress 2.5.1.</p>
<p><a href="http://wordpress.org/development/2008/04/wordpress-251/">Included</a> in the seventy fixes are several performance improvements for blogs with many categories and in the admin interface of Wordpress especially on the Dashboard, Write Post, and Edit Comments pages. I&#8217;m currently in the process of updating all my blogs and have not run into any problems yet. I usually do overwrite all files without disabling all plugins prior to this and I seldom encounter problems when updating Wordpress this way.</p>
<p>Most of the time it&#8217;s plugin related though. One note for all webmasters who are running Wordpress for some time now. Wordpress have added a new variable in the wp-config file called Secret Key. That variable introduces a little permanent randomness into the cryptographic functions used for cookies in WordPress. I suggest to update the Wordpress blogs as soon as possible, at least by uploading the files that are security related.</p>
<p><span id="more-3918"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/blog/" title="blog" rel="tag">blog</a>, <a href="http://www.ghacks.net/tag/blog-software/" title="blog software" rel="tag">blog software</a>, <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/11/25/wordpress-265-security-update/" title="Wordpress 2.6.5 Security Update (November 25, 2008)">Wordpress 2.6.5 Security Update</a> (0)</li>
	<li><a href="http://www.ghacks.net/2009/08/04/wordpress-2-8-3/" title="Wordpress 2.8.3 (August 4, 2009)">Wordpress 2.8.3</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/06/11/wordpress-2-8/" title="Wordpress 2.8 (June 11, 2009)">Wordpress 2.8</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/02/11/wordpress-271-update/" title="Wordpress 2.7.1 Update (February 11, 2009)">Wordpress 2.7.1 Update</a> (3)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/04/25/wordpress-251-released/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.3.3 Security Release</title>
		<link>http://www.ghacks.net/2008/02/05/wordpress-233-security-release/</link>
		<comments>http://www.ghacks.net/2008/02/05/wordpress-233-security-release/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 10:13:58 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Online Services]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2008/02/05/wordpress-233-security-release/</guid>
		<description><![CDATA[A new version of Wordpress has been released just a few hours ago by the Wordpress team. The update is considered critical and fixes a security vulnerability and some minor bugs. The security flaw was found in the implementation of the XML-RPC which would allow any registered user to edit comments of other users using a specially crafted request. ]]></description>
			<content:encoded><![CDATA[<p>A new version of Wordpress has been released just a few hours ago by the Wordpress team. The <a href="http://wordpress.org/download/">update</a> is considered critical and fixes a security vulnerability and <a href="http://trac.wordpress.org/query?status=closed&#038;milestone=2.3.3">some</a> minor bugs. The security flaw was found in the implementation of the XML-RPC which would allow any registered user to edit comments of other users using a specially crafted request. </p>
<p>Webmasters have two choices on how to secure and update their blog. The first is to use the official update process described on the Wordpress homepage which involves downloading the full distribution and replace the old files with it. A faster way which webmasters with a lot of blogs will probably prefer is to replace the xmlrpc.php with the updated one which will fix the security vulnerability but leave the minor bugs in place.</p>
<p>That&#8217;s probably the better solution if you never encountered them. The bugs will automatically be fixed with the next big release of Wordpress. Just make sure you update at least the security vulnerability in xmlrpc.php.</p>
<p><span id="more-3119"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/" title="Wordpress 2.8.6 Security Update (November 13, 2009)">Wordpress 2.8.6 Security Update</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/" title="Wordpress 2.8.5 Security Update (October 21, 2009)">Wordpress 2.8.5 Security Update</a> (4)</li>
	<li><a href="http://www.ghacks.net/2009/08/04/wordpress-2-8-3/" title="Wordpress 2.8.3 (August 4, 2009)">Wordpress 2.8.3</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/06/11/wordpress-2-8/" title="Wordpress 2.8 (June 11, 2009)">Wordpress 2.8</a> (5)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/02/05/wordpress-233-security-release/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.31 is available</title>
		<link>http://www.ghacks.net/2007/10/27/wordpress-231-is-available/</link>
		<comments>http://www.ghacks.net/2007/10/27/wordpress-231-is-available/#comments</comments>
		<pubDate>Sat, 27 Oct 2007 07:33:09 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[The Web]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[windows live writer]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2007/10/27/wordpress-231-is-available/</guid>
		<description><![CDATA[A new version of the blogging plattform Wordpress has been released today. It is an advised update for every webmaster especially for those with register_globals enabled. A security vulnerability was found that can be exploited if that setting is enabled. ]]></description>
			<content:encoded><![CDATA[<p>A new version of the blogging plattform Wordpress has been released today. It is an advised update for every webmaster especially for those with register_globals enabled. A security vulnerability was found that can be exploited if that setting is enabled. </p>
<p>The new version fixes more than 20 bugs and security vulnerabilities. Some of the most important fixes include tagging support for Windows Live Writer, a login fix for blogs that have different Wordpress and Blog addresses, faster taxonomy database queries, that emailed posts can now be assigned to the author if the email uses a hyphen and link importer fixes.</p>
<p>I had no troubles overwriting the files of my Wordpress installation to speed up the process. A suggestion would be to backup your blog before you start the process.</p>
<p><span id="more-2179"></span><strong>Read More:</strong></p>
<p><a href="http://wordpress.org/download/">Wordpress 2.31</a><br />
<a href="http://trac.wordpress.org/query?status=closed&#038;milestone=2.3.1&#038;resolution=fixed&#038;order=priority">Wordpress Release Notes</a></p>

	Tags: <a href="http://www.ghacks.net/tag/blog/" title="blog" rel="tag">blog</a>, <a href="http://www.ghacks.net/tag/script/" title="script" rel="tag">script</a>, <a href="http://www.ghacks.net/tag/windows-live-writer/" title="windows live writer" rel="tag">windows live writer</a>, <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/08/04/wordpress-2-8-3/" title="Wordpress 2.8.3 (August 4, 2009)">Wordpress 2.8.3</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/06/11/wordpress-2-8/" title="Wordpress 2.8 (June 11, 2009)">Wordpress 2.8</a> (5)</li>
	<li><a href="http://www.ghacks.net/2008/12/11/wordpress-27/" title="Wordpress 2.7 (December 11, 2008)">Wordpress 2.7</a> (7)</li>
	<li><a href="http://www.ghacks.net/2008/11/25/wordpress-265-security-update/" title="Wordpress 2.6.5 Security Update (November 25, 2008)">Wordpress 2.6.5 Security Update</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2007/10/27/wordpress-231-is-available/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Don&#8217;t upgrade to Wordpress 2.3 yet</title>
		<link>http://www.ghacks.net/2007/09/25/dont-upgrade-to-wordpress-23-yet/</link>
		<comments>http://www.ghacks.net/2007/09/25/dont-upgrade-to-wordpress-23-yet/#comments</comments>
		<pubDate>Tue, 25 Sep 2007 14:32:34 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[The Web]]></category>
		<category><![CDATA[ghacks]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress 2.3]]></category>
		<category><![CDATA[wordpress update]]></category>
		<category><![CDATA[wordpress upgrade]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2007/09/25/dont-upgrade-to-wordpress-23-yet/</guid>
		<description><![CDATA[The new version 2.3 of the blog script Wordpress has been released about 12 hours ago and lots of webmasters are starting to prepare their blogs to upgrade their version to the recent one. There is however one difficulty with this new release which will affect a lot of webmasters who try to upgrade their blog.]]></description>
			<content:encoded><![CDATA[<p>The new version 2.3 of the blog script Wordpress has been released about 12 hours ago and lots of webmasters are starting to prepare their blogs to upgrade their version to the recent one. There is however one difficulty with this new release which will affect a lot of webmasters who try to upgrade their blog.</p>
<p>The new version of Wordpress introduces some elementary changes to certain functions which can very well break a few plugins that are installed on the blog in question. Mostly plugins that deal with categories are affected. One that I&#8217;m using for instance is the plugin Simple Tagging but a handful of other plugins like Ultimate Tag Warrior, Popularity Contest and Ajax Comments are affected as well.</p>
<p>Those plugins display error messages when opening the website which does not look great and could limit the display of the blog as well. I tried to update one of my minor blogs first which has all the plugins installed that I use at Ghacks as well and found out that the only possibility for me was to deactivate the plugin in question.</p>
<p><span id="more-2045"></span>I suggest you build a local version of your blog and see if the upgrade to Wordpress 2.3 breaks the design or displays errors messages. If that is the case I would wait for plugin updates to be released before making the switch.</p>
<p><strong>Read More:</strong></p>
<p><a href="http://codex.wordpress.org/Plugins/Plugin_Compatibility/2.3">wordpress 2.3 Plugin Compatibility</a><br />
<a href="http://www.wordpress.org">wordpress 2.3 download</a></p>

	Tags: <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-23/" title="wordpress 2.3" rel="tag">wordpress 2.3</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a>, <a href="http://www.ghacks.net/tag/wordpress-upgrade/" title="wordpress upgrade" rel="tag">wordpress upgrade</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/" title="Wordpress 2.8.5 Security Update (October 21, 2009)">Wordpress 2.8.5 Security Update</a> (4)</li>
	<li><a href="http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/" title="Wordpress 2.8.6 Security Update (November 13, 2009)">Wordpress 2.8.6 Security Update</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/08/04/wordpress-2-8-3/" title="Wordpress 2.8.3 (August 4, 2009)">Wordpress 2.8.3</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/06/11/wordpress-2-8/" title="Wordpress 2.8 (June 11, 2009)">Wordpress 2.8</a> (5)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2007/09/25/dont-upgrade-to-wordpress-23-yet/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.2.2. released</title>
		<link>http://www.ghacks.net/2007/08/05/wordpress-222-released/</link>
		<comments>http://www.ghacks.net/2007/08/05/wordpress-222-released/#comments</comments>
		<pubDate>Sun, 05 Aug 2007 17:01:18 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress update]]></category>
		<category><![CDATA[wordpress vulnerabities]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2007/08/05/wordpress-222-released/</guid>
		<description><![CDATA[The Wordpress development team is releasing new versions of their popular blogging script faster and faster. It seems that I'm doing nothing else than to update my blog with the latest version of Wordpress. While not all updates are required some are important to apply as soon as they are released to close security vulnerabilities that could lead to a compromised blog if a hacker detects that your blog is not running the latest version.]]></description>
			<content:encoded><![CDATA[<p>The Wordpress development team is releasing new versions of their popular blogging script faster and faster. It seems that I&#8217;m doing nothing else than to update my blog with the latest version of Wordpress. While not all updates are required some are important to apply as soon as they are released to close security vulnerabilities that could lead to a compromised blog if a hacker detects that your blog is not running the latest version.</p>
<p><a href="http://www.wordpress.org/">Wordpress 2.2.2</a> is one of those updates that should be applied as soon as possible to make sure that your blog does not get compromised. Several of the <a href="http://trac.wordpress.org/query?status=closed&#038;milestone=2.2.2">vulnerabilities</a> are those that have been mentioned earlier by the guy who created the first Wordpress worm who fixed those vulnerabilities. Those are now the official updates from the Wordpress team.</p>
<p>4452	wpx can include invalid named entities in comment author name<br />
4477	Unfiltered post titles in Recent Comments widget<br />
4510	&#8220;WordPress requires at least 4.1&#8243; expression in wp-settings.php<br />
4522	Template: default broken<br />
4587	Restore comment editing fix that disabled rich text editing<br />
4629	deleted_link action is never called<br />
4683	category dropdown javascript wrong location after moved blog<br />
4692	Wordpress /edit-comments.php Database Error (Bug)<br />
4429	add_option followed by update_option not always working<br />
4689	Wordpress uploads.php Cross-Site Scripting Vulnerability</p>
<p><span id="more-1835"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/wordpress/" title="wordpress" rel="tag">wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a>, <a href="http://www.ghacks.net/tag/wordpress-vulnerabities/" title="wordpress vulnerabities" rel="tag">wordpress vulnerabities</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/" title="Wordpress 2.8.6 Security Update (November 13, 2009)">Wordpress 2.8.6 Security Update</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/" title="Wordpress 2.8.5 Security Update (October 21, 2009)">Wordpress 2.8.5 Security Update</a> (4)</li>
	<li><a href="http://www.ghacks.net/2009/08/04/wordpress-2-8-3/" title="Wordpress 2.8.3 (August 4, 2009)">Wordpress 2.8.3</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/06/11/wordpress-2-8/" title="Wordpress 2.8 (June 11, 2009)">Wordpress 2.8</a> (5)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2007/08/05/wordpress-222-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scan your Wordpress blog for vulnerabilities</title>
		<link>http://www.ghacks.net/2007/07/09/scan-your-wordpress-blog-for-vulnerabilities/</link>
		<comments>http://www.ghacks.net/2007/07/09/scan-your-wordpress-blog-for-vulnerabilities/#comments</comments>
		<pubDate>Mon, 09 Jul 2007 07:33:31 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Online Services]]></category>
		<category><![CDATA[The Web]]></category>
		<category><![CDATA[wordpress security]]></category>
		<category><![CDATA[wordpress update]]></category>
		<category><![CDATA[wordpress vulnerabilites]]></category>
		<category><![CDATA[wp scanner]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2007/07/09/scan-your-wordpress-blog-for-vulnerabilities/</guid>
		<description><![CDATA[Site owners should always be aware of the possibility that their blog gets compromised. This can be because of an old version of Wordpress that is installed or because of vulnerabilities in plugins or themes. It is relatively time consuming to check for updates and stay up to date to make it unlikely that someone would be able to hack your blog.]]></description>
			<content:encoded><![CDATA[<p>Site owners should always be aware of the possibility that their blog gets compromised. This can be because of an old version of Wordpress that is installed or because of vulnerabilities in plugins or themes. It is relatively time consuming to check for updates and stay up to date to make it unlikely that someone would be able to hack your blog.</p>
<p>The online security script Wordpress Scanner is a great tool which can be used to scan your Wordpress blog for several vulnerabilities such as outdated versions of Wordpress or single files and XSS vulnerabilities in themes. All you need to do is add the line <code><!-- wpscanner --></code> in the header of your blog so that the <a href="http://blogsecurity.net/wpscan" target="_blank">Wordpress Scanner</a> cgi script can access the information and knows that you are indeed the owner of the blog.</p>
<p>This tool is not perfect but it analyzes the versions of your Wordpress files which is probably the dominant attack vector when it comes to Wordpress hacking and basic XSS vulnerabilities in the themes. The tool gives advice if vulnerabilities have been found on how to fix them.</p>
<p><span id="more-1753"></span>Just make sure you run the script, follow the guidelines and remove the wpscanner entry from your header again. You would not want someone else to be able to check your blog for vulnerabilities, would not you ? This is a great little script which should become even better when the author adds checks for plugins.</p>

	Tags: <a href="http://www.ghacks.net/tag/wordpress-security/" title="wordpress security" rel="tag">wordpress security</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a>, <a href="http://www.ghacks.net/tag/wordpress-vulnerabilites/" title="wordpress vulnerabilites" rel="tag">wordpress vulnerabilites</a>, <a href="http://www.ghacks.net/tag/wp-scanner/" title="wp scanner" rel="tag">wp scanner</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/" title="Wordpress 2.8.6 Security Update (November 13, 2009)">Wordpress 2.8.6 Security Update</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/" title="Wordpress 2.8.5 Security Update (October 21, 2009)">Wordpress 2.8.5 Security Update</a> (4)</li>
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/11/25/wordpress-265-security-update/" title="Wordpress 2.6.5 Security Update (November 25, 2008)">Wordpress 2.6.5 Security Update</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/08/15/wordpress-261-released/" title="Wordpress 2.6.1 released (August 15, 2008)">Wordpress 2.6.1 released</a> (1)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2007/07/09/scan-your-wordpress-blog-for-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.2.1 Update</title>
		<link>http://www.ghacks.net/2007/06/21/wordpress-221-update/</link>
		<comments>http://www.ghacks.net/2007/06/21/wordpress-221-update/#comments</comments>
		<pubDate>Thu, 21 Jun 2007 14:54:36 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[The Web]]></category>
		<category><![CDATA[ghacks]]></category>
		<category><![CDATA[updating wordpress]]></category>
		<category><![CDATA[wordpress 2.2.1]]></category>
		<category><![CDATA[wordpress update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2007/06/21/wordpress-221-update/</guid>
		<description><![CDATA[The Wordpress development team released yet another update of the Wordpress blog script raising the version number to 2.2.1 in the process. This update contains several bug fixes that might have plagued some Wordpress blog owners while others - including myself - did not experience any of the bugs.

The more important part of this update is that it also fixes several security holes making it a required update for every webmaster. The vulnerabilities that have been fixed, they are:]]></description>
			<content:encoded><![CDATA[<p>The Wordpress development team released yet another update of the Wordpress blog script raising the version number to 2.2.1 in the process. This update contains several bug fixes that might have plagued some Wordpress blog owners while others &#8211; including myself &#8211; did not experience any of the bugs.</p>
<p>The more important part of this update is that it also fixes several security holes making it a required update for every webmaster. The vulnerabilities that have been fixed, they are:</p>
<ul>
<li>Remote shell injection in PHPMailer</li>
<li>Remote SQL injection in XML-RPC Discovered by Alexander Concha.</li>
<li>Unescaped attribute in default theme</li>
</ul>
<p><span id="more-1688"></span>I&#8217;m currently updating all my blogs with the new version which always takes a while. Make sure you download the official new version of <a href="http://wordpress.org/" target="_blank">Wordpress</a> and update your blog at once.</p>
<p>As a sidenote. I&#8217;m going on a short trip to Stockholm, Sweden tomorrow where I will stay until Monday. I&#8217;m really excited about this trip and if you got any last minute tips for me then let me know. I will update my blog in the coming days as well but it could be that i write less than usual. </p>

	Tags: <a href="http://www.ghacks.net/tag/updating-wordpress/" title="updating wordpress" rel="tag">updating wordpress</a>, <a href="http://www.ghacks.net/tag/wordpress-221/" title="wordpress 2.2.1" rel="tag">wordpress 2.2.1</a>, <a href="http://www.ghacks.net/tag/wordpress-update/" title="wordpress update" rel="tag">wordpress update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/11/13/wordpress-2-8-6-security-update/" title="Wordpress 2.8.6 Security Update (November 13, 2009)">Wordpress 2.8.6 Security Update</a> (5)</li>
	<li><a href="http://www.ghacks.net/2009/10/21/wordpress-2-8-5-security-update/" title="Wordpress 2.8.5 Security Update (October 21, 2009)">Wordpress 2.8.5 Security Update</a> (4)</li>
	<li><a href="http://www.ghacks.net/2009/08/04/wordpress-2-8-3/" title="Wordpress 2.8.3 (August 4, 2009)">Wordpress 2.8.3</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/07/20/wordpress-2-8-2-security-patch/" title="Wordpress 2.8.2 Security Patch (July 20, 2009)">Wordpress 2.8.2 Security Patch</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/06/11/wordpress-2-8/" title="Wordpress 2.8 (June 11, 2009)">Wordpress 2.8</a> (5)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2007/06/21/wordpress-221-update/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
