Archive for the 'Blogosphere' Category

WordPress 2.9.1 available

A new update has been released by WordPress, version 2.9.1.

This release addresses a handful of minor issues as well as a rather annoying problem where scheduled posts and pingbacks are not processed correctly due to incompatibilities with some hosts.

You can download the new version 2.9.1 from here, or upgrade automatically from your admin.

WordPress 2.9 available + built-in image editor

WordPress 29 available built-in image editorWordPress has finally announced the availability of WordPress version 2.9 “Carmen” named in honor of magical jazz vocalist Carmen McRae. WordPress 2.9 adds some features for image editing. This is a major upgrade, and brings some really cool new features, including:
+ Trash status for posts, pages, and comments (includes restore and permanent delete)
+ Built-in image editor (crop, edit, rotate, flip, and scale images)
+ Batch plugin update and compatibility checking (you can update multiple plugins at once) Continue reading ‘WordPress 2.9 available + built-in image editor’

WordPress 2.8.6 Security Update released

WordPress 286 Security Update releasedA new security update has been released by WordPress. Version 2.8.6 fixes two security problems that can be exploited by registered, logged in users who have posting privileges. If you have untrusted authors on your blog, upgrading to 2.8.6 is recommended.

The first problem is an XSS vulnerability in Press This discovered by Benjamin Flesch. The second problem, discovered by Dawid Golunski, is an issue with sanitizing uploaded file names that can be exploited in certain Apache configurations.

This is a security release, so upgrading is highly recommended. You can download the new version 2.8.6 from here, or upgrade automatically from your admin.

WordPress 2.8.5 Security Release available

WordPress 285 Security Release availableWordPress.org has updated its popular CMS to WordPress version 2.8.5. This is a security release, so upgrading is highly recommended.

You can download the new version 2.8.5 from here, or upgrade automatically from your admin.

The headline changes in this release are:
+ A fix for the Trackback Denial-of-Service attack that is currently being seen.
+ Removal of areas within the code where php code in variables was evaluated.
+ Switched the file upload functionality to be whitelisted for all users including Admins.
+ Retiring of the two importers of Tag data from old plugins.

(via wordpress)

How to Secure your WordPress blog Against Hacking?

How to secure your WordPress blog against hackingWordPress users warned of hacking worms! Recently, WordPress founder Matt Mullenweg has posted an article about keeping your WordPress installation safe. It discusses a worm which is targetting older versions of WordPress by creating a “hidden” admin user. The attack affects only self-hosted versions of WordPress (wordpress.org), not those at WordPress.com. The solution to avoid being attacked, if you have not done so already, update your WordPress install immediately to the latest version. Keeping your WordPress up to date is “taking your vitamins; fixing a hack is open heart surgery”. There are many WordPress security plugins you can use to secure your WordPress blog/site, but the essential thing you should not forget is upgrading to the latest version! Continue reading ‘How to Secure your WordPress blog Against Hacking?’