WordPress 2.8.6 is out! The release addresses two security problems:
- XSS vulnerability in Press This
- An issue with sanitizing uploaded file names that can be exploited in certain Apache configurations
It should be noted that blogs with untrusted logged in registered users who have posting privileges will face these security risks.

I’ve upgraded this blog to WordPress 2.8.6 from 2.8.5 without any problems — at least so far!
Tip: If you’re upgrading, as usual, always deactivate any plugins before an upgrade.
Although I could have upgraded WordPress from the admin pages, I did the upgrade using SimpleScripts. SimpleScripts did a barebones backup for me as part of the upgrading process. (A full backup is always recommended though! I’m just too lazy! Anyway, it’s just a 0.0.1 version upgrade…)
By the way, I’ve also given this blog a new look! Perhaps more about it another time.
Related posts:



