Peaches Posted February 9, 2011 Report Share Posted February 9, 2011 8 February 2011, 11:02 WordPress 3.0.5 addresses security vulnerabilities The WordPress.org development team has released version 3.0.5 of its open source blogging and publishing platform, a maintenance and security update that addresses two vulnerabilities; these could have allowed a Contributor- or Author-level user to gain further access to the site. An information disclosure issue has also been fixed that allowed Author-level users to view the contents of posts which they should not be able to see, such as draft and private posts. WordPress 3.0.5 features the addition of two new security enhancements, the first of which improves the security of plugins which were not properly utilising the platform's security API. The other provides better defence against a vulnerability that was fixed in the previous version. All users are encouraged to upgrade to the latest release as soon as possible. Additionally, the developers have released a fourth release candidate for version 3.1 of WordPress (direct download). WordPress 3.1 RC4 includes all of the enhancements and security fixes noted above, as well as fixes for approximately two dozen bugs. More details here: http://www.h-online.com/security/news/item/WordPress-3-0-5-addresses-security-vulnerabilities-1185082.html Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.