WordPress 2.8.6 Security Release : For People Who Have Untrusted Authors

Sell your mobile


You like this story?

wordpress-updateRecently (November 12) WordPress have released another update 2.8.6! This is a security update which fixes several security issues detected while testing the system. Actually its very important for us to put these security updates….. as I think, if you have a website, the first thing you must ensure is the security, because the net is a very un-secure place! Before updating, lets see what have they fixed!


As they say the first Problem is an XSS vulnerability which is also known as Cross-site Scripting. It is found in web applications which enable malicious attackers to inject client-side script into web pages viewed by other users. An exploited cross-site scripting vulnerability can be used by attackers to bypass access controls such as the same origin policy. (Info from Wikipedia)

The second one, is an issue with sanitizing uploaded file names that can be exploited in certain Apache configurations. Which have been discovered by Dawid Golunski.


Now what do we have to do?

What we have to do is backup our WordPress system and put this update to save our skins! Lets see how to do it :



Congrats! If you follow the above steps, your now secured! But, that doesn’t mean that your completely secured…. remember what I said, the net is a very unsecured place! So, here-after make sure that your WordPress system is up-to-date!



Line Break

Author: Pubudu Kodikara (254 Articles)

Pubudu Kodikara is a writer at Tech Hamlet (www.techhamlet.com), a state of the art tech blog which is powered by the Earth Organization, which have a main target of educating people about the latest technology. They post latest tech news, tips on how to resolve problems, tricks and hacks to improve what you do, tutorials to learn new things and many more.

Comments
  • Harsh Agrawal
    Harsh Agrawal November 13, 2009 at 7:37 am

    This update was really unexpected.. though this update seems to be only for those
    who have multi author blogs or is it for every one?

    • Pubudu
      Pubudu November 13, 2009 at 3:31 pm

      Specially for multiuser blogs… but its better if everyone can put this update! :D

  • Lets Add a Comment
    CommentLuv Enabled

     

Get Adobe Flash playerPlugin by wpburn.com wordpress themes
Anti Malware Antivirus anti virus blog blogging Computer Security Contests E-mail Facebook Firefox freeware gmail GNU GRUB Google Google Chrome Graphics internet marketing Internet Security Linux Lucid Lynx Microsoft Microsoft Windows Mozilla Firefox Online Security Open source Operating system Search engine optimization Security social network Social Networking Software System Utilities Tech Hamlet TechHamlet TechHamlet Forums Twitter Ubuntu Utilities Web Web browser Website Web Tools Windows Windows 7 WordPress

© 2009 - 2010 Tech Hamlet (Version 7.1) Sri Lanka