WordPress 2.3.3 Vulnerabilities?

Verne Ho, the owner of Creative Briefing, has e-mailed me about having some problems with his blog resulting in errors for his visitors and users. He states in the e-mail that he did some investigating and found out it might be something wrong with WordPress 2.3.3. “Upon investigation, I discovered something that might suggest a vulnerability in WordPress 2.3.3. I haven’t been able to find much information on the issue so I decided to document my own findings.” he states in the e-mail.

Has anyone else been having problems like Verne? I haven’t experienced anything yet and I’m hoping I won’t have since WordPress 2.5 is scheduled for release within the next few days.

If you have been having problems like Verne, he’s posted an article on his blog for a temporary fix to solve this. If you’re interested, check it out here.

WordPress 2.5

I’m pretty excited about WordPress 2.5 being (hopefully) released sometime in March. According to the WordPress Roadmap, 2.5 it’s set to be released on March 10, 2008, which is a little less than a month from today.

Read more…

WordPress 2.3.3

Hey everyone, just a quick post letting you all know WordPress 2.3.3 has been released. According to WordPress.org, there was a flaw in their XML-RPC implementation, “such that a specially crafted request would allow any valid user to edit posts of any other user on that blog.” WordPress 2.3.3 also fixes a few minor bugs, so it looks like it’ll be a good idea to upgrade.

If you are interested only in the security fix, download the fixed version of xmlrpc.php and copy it over your existing xmlrpc.php. Otherwise, you can just download the whole release.

XMLRPC.php - Fixed Version

WordPress 2.3.3 - Full Version

WordPress Community News

During the last couples of days I’ve seen some pretty neat stuff coming from different blogs throughout the WordPress Community. The WordPress Community is a pretty big place. A while back, I read 0.8% of the Internet is powered by WordPress. Woah! Now, 0.8% may not seem a lot, but think about it, at least a couple hundred sites are created a day.

Anyway, I’ll be going through some cool WordPress related stuff you should check out!

Read more…