WordPress 2.8.2 released with an XSS Vulnerability fix

Written by EarnBlogger on July 20, 2009 Posted in: Wordpress

The developers at WordPress has released a new version of the popular blogging software. Another WordPress update within two weeks? Yes, WordPress 2.8.2 is here and it fixes an XSS vulnerability in which comment author URLs were not fully sanitized when displayed in the admin. This security hole could easily be exploited to redirect the site admin away from the admin page to another site.

This is the second release of WordPress within a month. WordPress 2.8.1 was released earlier this month, on July 9, and it came with many bug fixes and enhanced security for plugin admin pages. Now, just after 10 days another version of WordPress arrives. Why? It must really be a serious update.  Don’t ignore the XSS (Cross Site Scripting) vulnerability and get WordPress 2.8.2 today. Download it from the official site or upgrade automatically from your WordPress admin page.

Via: http://wordpress.org/development/2009/07/wordpress-2-8-2/

So far, 2 responses to “WordPress 2.8.2 released with an XSS Vulnerability fix”. Add your own!

  1. Alvin Tan says:

    Thanks for sharing. I have just upgraded to version 2.8.2.

  2. Some fast update from the WordPress Theme.I do believe many bloggers will find this new update confusing. Who can blame them? They just installed the latest weeks ago and now, this one came in.

Leave a Reply