WordPress 2.3.2 Released – Security

calendar Posted on December 30, 2007   comments 3 Comments

WordPress Logo This past Friday I saw a post at CyberNet News about a WordPress vulnerability related to how future dated posts (and drafts?) could be seen by non-authorized folks.

Yesterday a new version (2.3.2) of WordPress was released and Peter Westwood offers details on what’s all involved. Definitely worth a read if you’re curious about what to expect in the new release. Among other things, it does address the above vulnerability.

I want to point out one item that caught my eye:

Support for a custom database down page to be displayed on database connection errors (#5500).

From the announcement post, it seems that your custom database error page should be in wp-content/db-error.php. I sure wish that would’ve been theme specific instead — wouldn’t that be more logical? But still, it’s a nice step and, if nothing else, will offer some creativity to all those digg-killed shared-hosting blogs. ;-)

tags Tags: , , ,

Comments

3 Responses to “WordPress 2.3.2 Released – Security”

  1. The custom database error page can’t be theme specific [because] WordPress needs database access in order to know what the current theme is.

  2. Chris Kasten says:

    Oh geeze… ok that makes sense. I guess I didn’t think it all the way through.

    Thanks for stopping by and clarifying :-)

  3. Yair says:

    during the last few months a few WordPress vulnerabilities were discovered that allowed hackers to inject links into blogs. I find it unbelievable that there is still no solution to this problem.
    I heard about the latest wordpress vulnerability from this vulnerability scanner
    http://www.beyondsecurity.com/vulnerability-scanner.html
    I guess the only way to learn about new vulnerabilities is to wait for someone else to get hurt and to protect yourself as soon as you get the news.

Leave a Reply

Please read the "Comments" section on the Disclaimer page. Don't use SEO terms instead of a name. That drives me nuts.
Oh, and contrary to what you might have read on some SEO forum, this is not a "Do Follow" blog.



About

Wandering the Internet, looking at all things bright and shiny. Playing with many, writing about some. More …

Recent Posts

Recent Comments: