Sep 9 2008

WordPress 2.6.2

If you're new here, you may want to browse my articles and if you like them please subscribe to my RSS feed. Thanks for visiting!

WordPress 2.6.2 s the latest release less than a month after WordPress 2.6.1.  Looks like another minor upgrade and is recommended if you allow open registration on your blog.

With open registration enabled, it is possible in WordPress versions 2.6.1 and earlier to craft a username such that it will allow resetting another user’s password to a randomly generated password.  Its not a security threat as the randomly generated password is not disclosed to the attacker but its a problem by itself which is annoying.  However, this attack coupled with a weakness in the random number seeding in mt_rand() could be used to predict the randomly generated password.  Stefan Esser will release details of the complete attack shortly.  The attack is difficult to accomplish,  but its mere possibility means we recommend upgrading to 2.6.2.

Other PHP apps are susceptible to this class of attack.  To protect all of your apps, grab the latest version of Suhosin.  If you’ve already updated Suhosin, your WordPress is protected.

WordPress 2.6.2 also contains a handful of bug fixes.  Check out the full changeset and list of changed files.

I have just updated my blog and will do the same on the others I own too….

Popularity: 36% [?]

Related Posts

  • WordPress 2.5 Has Arrived…
  • Why WordPress is so Popular
  • WordPress 2.5
  • WordPress 2.6 and Beyond
  • Wordpress Automatic Upgrade Plugin


  • Popular Posts

  • 35 RSS Feed Sites To Promote Your Site
  • 25 + 1 Tips to Increase your Subscribers
  • Adding Your Blog Feed to Twitter
  • 9 Blog Rankings and How to Manipulate-Part Two
  • Stumble Exchange Sites


  • If you found this page useful, consider linking to it.
    Simply copy and paste the code below into your web site (Ctrl+C to copy)
    It will look like this: WordPress 2.6.2

    2 Comments on this post

    Trackbacks

    1. Wordpress Themes wrote:

      Wordpress Themes…

      I have been using WordPress for about 2 years now. All this time, I left it to WordPress default settings to get my latest blog post updated with the major blog directories and blog search engines….

      October 8th, 2008 at 5:35 am
    1. sohbet said:

      thanks

      October 31st, 2008 at 11:08 pm

    LEAVE A COMMENT

    Subscribe Form

    Subscribe to Blog

    Sponsors

    Popular Posts

    Recent Comments

    • Leo: If it were only that easy….keyword density isn’t really as important as it were a couple years back....
    • Dawn Hall: Great article, I have already implemented, will wait and reap the rewards. Thanks!
    • Josh the Business Plan Guy: Thanks for the info. The more sites there are like this, the better. A lot of people can...
    • nuaeman: Thanks for the info. I will give a try to Bukisa. At this moment I involve with Triond and AC. Hope Bukisa...
    • Jarrad: thanks for these tips, I have been doing a bit of reading on SEO lately and have found your information quite...
    • Arian "christmas shopping" Mae: Wow, this is so cool. This is one of those easy ways on earning money online. Thank...

    Recent Readers

    JOIN MY COMMUNITY!