No Mod Required

Wordpress users…

WordPress 2.3.3 is out.

Since it fixes a security issue there's no better time than now to upgrade…

WordPress 2.3.3 is an urgent security release. If you have registration enabled a flaw was found in the XML-RPC implementation such that a specially crafted request would allow a user to edit posts of other users on that blog. In addition to fixing this security flaw, 2.3.3 fixes a few minor bugs. If you are interested only in the security fix, download the fixed version of xmlrpc.php and copy it over your existing xmlrpc.php. Otherwise, you can get the entire release here.

Also, there is a vulnerability in the WP-Forum plugin that is being actively exploited right now. If you are using this plugin, please remove it until an update is available from its author.

Since we are talking security, remember to use strong passwords and change them regularly. While you’re updating WP and your plugins, consider refreshing your passwords.

Speaking of Wordpress, does anyone know why Akismet suddenly sucks? The past few days it's consistently been beaten by trackback spam touting the night vision exploits of a certain hotel heiress. It's the EXACT same URL, with the EXACT same text and formatting, but it keeps getting through. I've had a handful of false negatives over the years I've used it (a few a month) and all of a sudden I've seen dozens of identical examples in just the past week.

Is someone gaming the system?

What Other People Are Saying

Want to join in the discussion? Leave a comment using the form below or link to http://www.drunkenfist.com/304/2008/02/05/wordpress-users/ from your own site to have your post show up here.

Leave a Reply

Note: Wrap all of your code blocks in <code>...</code> and replace < and > with &lt; and &gt;, respectively.