Home » blog

New Release: WordPress 2.8.5

21 October 2009 4 Comments

As you know over the past couple of months we have been working on the new features for WordPress 2.9. We have also been working on trying to make WordPress as secure as possible and during this process we have identified a number of security hardening changes that we thought were worth back-porting to the 2.8 branch so as to get these improvements out there and make all your sites as secure as possible.

The headline changes in this release are:

* A fix for the Trackback Denial-of-Service attack that is currently being seen.
* Removal of areas within the code where php code in variables was evaluated.
* Switched the file upload functionality to be whitelisted for all users including Admins.
* Retiring of the two importers of Tag data from old plugins.

We would recommend that all sites are upgraded to this new version of WordPress to ensure that you have the best available protection.

If you think your site may have been hit by one of the recent exploits and you would like to make sure that you have cleared out all traces of the exploit then we would recommend that you take a look at the WordPress Exploit Scanner. This is a plugin which searches the files on your website, and the posts and comments tables of your database for anything suspicious. It also examines your list of active plugins for unusual filenames. You can read more about this plugin here – “WordPress Exploit Scanner“

Download Wordpress 2.8.5

Source: http://wordpress.org/development/2009/10/wordpress-2-8-5-hardening-release/

Related posts:

  1. New WordPress 2.9 Released
  2. WordPress 2.8.6 Security Release
  3. Alexa Rank and How To Add Alexa Widget
  4. Free Download Smadav Rev 8.1 – Update 5 Maret 2010
  5. How to Create a Blog in WordPress.com

4 Comments »

  • Paman Gober said:

    Sounds great, Wp 2.8.5 is released and I can’t wait for Wp 2.9

  • mbah gendeng said:

    maaf baru sempat mampir yup bagus juga nih tapi masih belum sempat untuk ngupdate masih beres2 blog yg sempat rusak dulu

  • apeltepay said:

    Other variant is possible also

  • Plallrurgycer said:

    Very Recently, there has been a great deal of investigation by the
    FTC against bloggers and website developers
    for not publishing their advertising profits, or potential
    connections with ad networks.

    What are your ideas about how this could potentially impact
    the blogging world?

Leave your response!

Be nice. Keep it clean. Stay on topic. No spam.