Home » blog

WordPress 2.8.6 Security Release

13 November 2009 2 Comments

2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges. If you have untrusted authors on your blog, upgrading to 2.8.6 is recommended.

The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch. The second problem, discovered by Dawid Golunski, is an issue with sanitizing uploaded file names that can be exploited in certain Apache configurations. Thanks to Benjamin and Dawid for finding and reporting these.

http://wordpress.org/development/2009/11/wordpress-2-8-6-security-release/

Related posts:

  1. New Release: WordPress 2.8.5
  2. How to Create a Blog in WordPress.com
  3. How to Get Free Renewal Domain CO.CC
  4. New WordPress 2.9 Released

Incoming search terms for the article:

uninstal smadaf-keygen smadav 7 5-link:http://www jcpenney com/products/Cg12706 jsp -site:www jcpenney com-

2 Comments »

Leave your response!

Be nice. Keep it clean. Stay on topic. No spam.