Browse >

| Subscribe via RSS / EMAIL

WordPress 2.6.5

| |

There is not and never will be a version 2.6.4

Just woke up this afternoon, checked my emails and other social networking website I have when suddenly a post from Mr. Bob Reyes on Multiply caught up my attention, it reads, "WordPress 2.6.5 is out now!"

Upon checking Wordpress.org, here's the development update of the said released:
The security issue is an XSS exploit discovered by Jeremias Reith that fortunately only affects IP-based virtual servers running on Apache 2.x. If you are interested only in the security fix, copy wp-includes/feed.php and wp-includes/version.php from the 2.6.5 release package.

2.6.5 contains three other small fixes in addition to the XSS fix. The first prevents accidentally saving post meta information to a revision. The second prevents XML-RPC from fetching incorrect post types. The third adds some user ID sanitization during bulk delete requests. For a list of changed files, consult the full changeset between 2.6.3 and 2.6.5.

Note that we are skipping version 2.6.4 and jumping from 2.6.3 to 2.6.5 to avoid confusion with a fake 2.6.4 release that made the rounds. There is not and never will be a version 2.6.4.

img-520-wp_265

a sample image of full changeset



And I asked myself.. "should I downgrade?"

Download: WordPress 2.6.5 | Mirror

0 comments: