The Best Super Affiliate You’ve Never Heard Of!
Once again, another security release from the guys at WordPress.
With no word on when the elusive v2.7 will be released, it’s probably best that everyone update to 2.6.5 to keep their blogs secure. If you are interested only in the security fix, copy wp-includes/feed.php and wp-includes/version.php from the 2.6.5 release package.
2.6.5 contains three other small fixes in addition to the XSS fix. The first prevents accidentally saving post meta information to a revision. The second prevents XML-RPC from fetching incorrect post types. The third adds some user ID sanitization during bulk delete requests.
In order to avoid confusion with a fake 2.6.4. release that made it’s way across the web, they’ve skipped ahead from 2.6.3 to 2.6.5. There is not and never will be a version 2.6.4.
Get Updates Straight To Your Inbox
Tweet This Post!
Leave a reply