November 26, 2008
3:10 am

The WordPress dev team released WordPress 2.6.5 – a security release that fixes one security problem and three bugs. The security issue is an XSS exploit that only affects IP-based virtual servers running on Apache 2.x. If you are interested only in the security fix, copy wp-includes/feed.php and wp-includes/version.php from the 2.6.5 release package.

2.6.5 contains three other small fixes in addition to the XSS fix. The first prevents accidentally saving post meta information to a revision. The second prevents XML-RPC from fetching incorrect post types. The third adds some user ID sanitization during bulk delete requests. For a list of changed files, consult the full changeset between 2.6.3 and 2.6.5.

Download

Loading

Contextual Related Posts:

No followup yet

Leave a Response

Comment Preview
« GoDaddy $1.19 for 1 year Domain Name RegistrationWindows Home Server Toolkit Released »
Feed Icon

Subscribe via RSS or email: