WordPress 2.8.4 Released

WordPress have released 2.8.4 to address a security issue. Seems like hackers could have caused a lot of problems with this.

Yesterday a vulnerability was discovered: a specially crafted URL could be requested that would allow an attacker to bypass a security check to verify a user requested a password reset. As a result, the first account without a key in the database (usually the admin account) would have its password reset and a new password would be emailed to the account owner. This doesn’t allow remote access, but it is very annoying.

If you are using 2.7+ then you should be able to update WordPress directly from your admin area. If you are using an older version, I recommend downloading and installing the latest release.

Better safe than sorry!

Kevin

Twitter Icon

Tweet This Post

No Responses so far | Have Your Say!

Leave a Comment

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Our Blog