Information from WordPress.org.
WordPress 2.3.3 is an urgent security release. A flaw was found in our XML-RPC implementation such that a specially crafted request would allow any valid user to edit posts of any other user on that blog. In addition to fixing this security flaw, 2.3.3 fixes a few minor bugs. If you are interested only in the security fix, download the fixed version of xmlrpc.php and copy it over your existing xmlrpc.php. Otherwise, you can get the entire release here.
If you run a WordPress server installation, it’s important that you download and install this update now.













1 response so far ↓
1 Matt Ellsworth // Feb 5, 2008 at 6:21 pm
I saw this earlier and went through and updated my blogs. I was shocked to see another patch come out - I wasn’t expecting anything till wp 2.5
Matt Ellsworth’s last blog post: Yicrosoft Directory - Say What?
Leave a Comment